MEDIUM5.4
GHSA-7jvx-f994-rfw2
materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input
Details
All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/materialize-css
Introduced in:
0No fixed version published yet for materialize-css (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25349[ADVISORY]
- https://github.com/Dogfalo/materialize[PACKAGE]
- https://github.com/Dogfalo/materialize/blob/v1-dev/js/autocomplete.js%23L285%20[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2766498[WEB]
- https://snyk.io/vuln/SNYK-JS-MATERIALIZECSS-2324800[WEB]