Lucene search

K
osvGoogleOSV:GHSA-MHP6-PXH8-R675
HistoryJun 18, 2020 - 2:19 p.m.

Cross site scripting in Angular

2020-06-1814:19:58
Google
osv.dev
14

0.002 Low

EPSS

Percentile

51.9%

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping <option> elements in <select> ones changes parsing behavior, leading to possibly unsanitizing code.

CPENameOperatorVersion
angularlt1.8.0

References