Description
Versions of jquery.terminal prior to 1.21.0 are vulnerable to Reflected Cross-Site Scripting. If the application has either of the options anyLinks or invokeMethods set to true, the application may execute arbitrary JavaScript through crafted malicious payloads due to insufficient sanitization.
Recommendation
Update the jquery.terminal package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.21.0
- Patched version(s): 1.21.0
References
Related Issues
- VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability - CVE-2024-29271
- Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site - Vulnerability
- Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability - CVE-2024-43407
- Reflected cross-site scripting (XSS) vulnerability - CVE-2022-0087
You might also like:
- Tags:
- npm
- jquery.terminal
Anything's wrong? Let us know Last updated on January 09, 2023


