VDB
Sign up
MEDIUM6.1

GHSA-8wp9-x25p-8794

tarteaucitron Cross-site Scripting (XSS)

Quick fix

GHSA-8wp9-x25p-8794 — tarteaucitronjs: upgrade to the fixed version with the command below.

npm install tarteaucitronjs@1.17.0

Details

Versions of the package tarteaucitronjs before 1.17.0 are vulnerable to Cross-site Scripting (XSS) via the getElemWidth() and getElemHeight(). This is related to [SNYK-JS-TARTEAUCITRONJS-8366541](https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-8366541)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/tarteaucitronjs
Introduced in: 0Fixed in: 1.17.0
Fixnpm install tarteaucitronjs@1.17.0

References