MEDIUM5.4
GHSA-h3cq-j957-vhxg
Cross-site Scripting in fullpage.js
Quick fix
GHSA-h3cq-j957-vhxg — fullpage.js: upgrade to the fixed version with the command below.
npm install fullpage.js@4.0.5Details
using fullpage.js you can create a anchor tag . But when put href in anchor then it does not sanitize the url which allow for a break in the context of anchor element and can add our new element.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-1330[ADVISORY]
- https://github.com/alvarotrigo/fullPage.js/pull/4360[WEB]
- https://github.com/alvarotrigo/fullpage.js/commit/e7a5db42711700c8a584e61b5e532a64039fe92b[WEB]
- https://github.com/alvarotrigo/fullpage.js[PACKAGE]
- https://huntr.dev/bounties/08d2a6d0-772f-4b05-834e-86343f263c35[WEB]