Vulnerabilities/

jquery.terminal self XSS on user input

Severity:
Low

Description

This is low impact and limited XSS, because code for XSS payload is always visible, but attacker can use other techniques to hide the code the victim sees.

Also if the application use execHash option and execute code from URL the attacker can use this URL to execute his code.

Recommendation

Update the jquery.terminal package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jquery.terminal
Anything's wrong? Let us know Last updated on January 30, 2023

This issue is available in SmartScanner Professional

See Pricing