Vulnerabilities/

tarteaucitron.js allows url scheme injection via unfiltered inputs

Severity:
Medium

Description

A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site’s source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert().

Recommendation

Update the tarteaucitronjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tarteaucitronjs
Anything's wrong? Let us know Last updated on April 07, 2025

This issue is available in SmartScanner Professional

See Pricing