GHSA-8cpw-73f2-w58m
Dashboard / Vulnerabilities / GHSA-8cpw-73f2-w58m
Summary: Cross-Site Scripting in selectize-plugin-a11y
Details: Versions of `selectize-plugin-a11y ` prior to 1.1.0 are vulnerable to Cross-Site Scripting. The `accessibility.liveRegion.speak` function does not sanitize the `msg` variable before rendering it as HTML. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim's browser. ## Recommendation Upgrade to version 1.1.0 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-15482, https://github.com/SLMNBJ/selectize-plugin-a11y/pull/9, https://www.npmjs.com/advisories/1145, https://www.npmjs.com/package/selectize-plugin-a11y/v/1.1.0
Affected packages
Package
Name: selectize-plugin-a11y
Purl: pkg:npm/selectize-plugin-a11y
Affected ranges
Type: SEMVER
Events:
