VDB
Sign up
MEDIUM6.1

GHSA-prc3-vjfx-vhm9

Angular (deprecated package) Cross-site Scripting

Details

All versions of package angular are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of `<textarea>` elements.

NPM package [angular](https://www.npmjs.com/package/angular) is deprecated. Those who want to receive security updates should use the actively maintained package [@angular/core](https://www.npmjs.com/package/@angular/core).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/angular
Introduced in: 0

No fixed version published yet for angular (npm). Pin to a known-safe version or switch to an alternative.

References