MEDIUM
GHSA-2hwp-g4g7-mwwj
Reflected Cross-Site Scripting in jquery.terminal
Quick fix
GHSA-2hwp-g4g7-mwwj — jquery.terminal: upgrade to the fixed version with the command below.
npm install jquery.terminal@1.21.0Details
Versions of `jquery.terminal` prior to 1.21.0 are vulnerable to Reflected Cross-Site Scripting. If the application has either of the options `anyLinks` or `invokeMethods` set to true, the application may execute arbitrary JavaScript through crafted malicious payloads due to insufficient sanitization.
## Recommendation
Upgrade to version 1.21.0 or later
Are you affected?
Enter the version of the package you're using.