AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes
Moderate severity
GitHub Reviewed
Published
Feb 14, 2020
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jan 2, 2020
Reviewed
Feb 13, 2020
Published to the GitHub Advisory Database
Feb 14, 2020
Last updated
Jan 27, 2023
Versions of
angular
prior to 1.5.0-beta.1 are vulnerable to Cross-Site Scripting. The package fails to sanitizexlink:href
attributes, which may allow attackers to execute arbitrary JavaScript in a victim's browser if the value is user-controlled.Recommendation
Upgrade to version 1.5.0-beta.1 or later.
References