Vulnerabilities/

XSS in knockout

Severity:
Medium

Description

There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

Recommendation

Update the knockout package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
knockout
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing