Vulnerabilities/

Materialize-css vulnerable to Cross-site Scripting in autocomplete component (GHSA-7752-f4gf-94gc)

Severity:
Medium

Description

All versions of materialize-css are vulnerable to Cross-Site Scripting. The autocomplete component does not sufficiently sanitize user input, allowing an attacker to execute arbitrary JavaScript code if the malicious input is rendered by a user.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
materialize-css
Anything's wrong? Let us know Last updated on August 28, 2023

This issue is available in SmartScanner Professional

See Pricing