Vulnerabilities/

Valine HTML Injection

Severity:
Medium

Description

An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.

Recommendation

Update the valine package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
valine
Anything's wrong? Let us know Last updated on September 07, 2023