Lucene search

K
nodejsPaulyiNODEJS:1145
HistorySep 04, 2019 - 6:50 p.m.

Cross-Site Scripting

2019-09-0418:50:03
paulyi
www.npmjs.com
9

EPSS

0.001

Percentile

29.3%

Overview

Versions of selectize-plugin-a11y prior to 1.1.0 are vulnerable to Cross-Site Scripting. The accessibility.liveRegion.speak function does not sanitize the msg variable before rendering it as HTML. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim’s browser.

Recommendation

Upgrade to version 1.1.0 or later.

References

EPSS

0.001

Percentile

29.3%