Cross-Site Scripting in @risingstack/protect
Moderate severity
GitHub Reviewed
Published
Apr 25, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Apr 25, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
All versions of
@risingstack/protect
are vulnerable to Cross-Site Scripting. TheisXss()
XSS validator has several bypasses that may allow attackers to execute arbitrary JavaScript in a victim's browser.Recommendation
No fix is currently available. Consider using an alternative package. The package is not actively maintained and will not be patched.
References