MEDIUM6.1
GHSA-98f7-p5rc-jx67
Materialize-css vulnerable to Cross-site Scripting in tooltip component
Quick fix
GHSA-98f7-p5rc-jx67 — @materializecss/materialize: upgrade to the fixed version with the command below.
npm install @materializecss/materialize@1.1.0-alphaDetails
All versions of `materialize-css` are vulnerable to Cross-Site Scripting. The `tooltip` component does not sufficiently sanitize user input, allowing an attacker to execute arbitrary JavaScript code if the malicious input is rendered by a user.
## Recommendation
No fix is currently available. Consider using an alternative module until a fix is made available.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/materialize-css
Introduced in:
0No fixed version published yet for materialize-css (npm). Pin to a known-safe version or switch to an alternative.
npm/@materializecss/materialize
Introduced in:
0Fixed in: 1.1.0-alphaFix
npm install @materializecss/materialize@1.1.0-alphaReferences
- https://nvd.nist.gov/vuln/detail/CVE-2019-11002[ADVISORY]
- https://github.com/Dogfalo/materialize/issues/6286[WEB]
- https://github.com/materializecss/materialize/pull/49[WEB]
- https://github.com/Dogfalo/materialize[PACKAGE]
- https://github.com/advisories/GHSA-98f7-p5rc-jx67[ADVISORY]
- https://snyk.io/vuln/SNYK-JS-MATERIALIZECSS-174148[WEB]
- https://www.npmjs.com/advisories/818[WEB]