CVE-2022-1330
Dashboard / Vulnerabilities / CVE-2022-1330
Summary: stored xss due to unsantized anchor url in alvarotrigo/fullpage.js
Details: stored xss due to unsantized anchor url in GitHub repository alvarotrigo/fullpage.js prior to 4.0.4. stored xss .
References: https://huntr.dev/bounties/08d2a6d0-772f-4b05-834e-86343f263c35, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1330.json, https://nvd.nist.gov/vuln/detail/CVE-2022-1330, https://github.com/alvarotrigo/fullpage.js/commit/e7a5db42711700c8a584e61b5e532a64039fe92b
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
4.0.3
4.0.2
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
