Vulnerabilities/

Materialize-css vulnerable to Cross-site Scripting in autocomplete component

Severity:
Medium

Description

All versions of materialize-css are vulnerable to Cross-Site Scripting. The autocomplete component does not sufficiently sanitize user input, allowing an attacker to execute arbitrary JavaScript code if the malicious input is rendered by a user.

Recommendation

Update the @materializecss/materialize package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@materializecss/materialize
Anything's wrong? Let us know Last updated on August 28, 2023

This issue is available in SmartScanner Professional

See Pricing