GHSA-7jvx-f994-rfw2
Dashboard / Vulnerabilities / GHSA-7jvx-f994-rfw2
Summary: materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input
Details: All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-25349, https://github.com/Dogfalo/materialize, https://github.com/Dogfalo/materialize/blob/v1-dev/js/autocomplete.js%23L285%20, https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2766498, https://snyk.io/vuln/SNYK-JS-MATERIALIZECSS-2324800
Affected packages
Package
Name: materialize-css
Purl: pkg:npm/materialize-css
Affected ranges
Type: SEMVER
Events:
