Vulnerabilities/

Reflected Cross-Site Scripting in jquery.terminal

Severity:
Medium

Description

Versions of jquery.terminal prior to 1.21.0 are vulnerable to Reflected Cross-Site Scripting. If the application has either of the options anyLinks or invokeMethods set to true, the application may execute arbitrary JavaScript through crafted malicious payloads due to insufficient sanitization.

Recommendation

Update the jquery.terminal package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jquery.terminal
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing