Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThjcHctNzNmMi13NTht
Cross-Site Scripting in selectize-plugin-a11y
Versions of selectize-plugin-a11y
prior to 1.1.0 are vulnerable to Cross-Site Scripting. The accessibility.liveRegion.speak
function does not sanitize the msg
variable before rendering it as HTML. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim's browser.
Recommendation
Upgrade to version 1.1.0 or later.
Permalink: https://github.com/advisories/GHSA-8cpw-73f2-w58mJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThjcHctNzNmMi13NTht
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 5 years ago
Updated: almost 2 years ago
CVSS Score: 6.1
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Percentage: 0.00066
EPSS Percentile: 0.30507
Identifiers: GHSA-8cpw-73f2-w58m, CVE-2019-15482
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-15482
- https://github.com/SLMNBJ/selectize-plugin-a11y/pull/9
- https://www.npmjs.com/package/selectize-plugin-a11y/v/1.1.0
- https://www.npmjs.com/advisories/1145
- https://github.com/advisories/GHSA-8cpw-73f2-w58m
Blast Radius: 3.7
Affected Packages
npm:selectize-plugin-a11y
Dependent packages: 0Dependent repositories: 4
Downloads: 5,969 last month
Affected Version Ranges: < 1.1.0
Fixed in: 1.1.0
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4
All unaffected versions: 1.1.0