Vulnerabilities/

Slim Select has potential Cross-site Scripting issue

Severity:
Medium

Description

Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is assigned to an innerHTML without sanitation.

Recommendation

Update the slim-select package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
slim-select
Anything's wrong? Let us know Last updated on October 18, 2024

This issue is available in SmartScanner Professional

See Pricing