Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client
High severity
GitHub Reviewed
Published
Aug 31, 2023
in
decentraland/single-sign-on-client
•
Updated Nov 5, 2023
Description
Published by the National Vulnerability Database
Sep 1, 2023
Published to the GitHub Advisory Database
Sep 4, 2023
Reviewed
Sep 4, 2023
Last updated
Nov 5, 2023
Impact
Improper input validation in the
init
function allows arbitrary javascript to be executed using thejavascript:
prefixPatches
This vulnerability was patched on version
0.1.0
Workarounds
This vulnerability can be prevented if user input correctly sanitized or there is no user input pass to the
init
functionReferences