MEDIUM6.1
GHSA-rg3q-jxmp-pvjj
Materialize-css vulnerable to Improper Neutralization of Input During Web Page Generation
Quick fix
GHSA-rg3q-jxmp-pvjj — @materializecss/materialize: upgrade to the fixed version with the command below.
npm install @materializecss/materialize@1.1.0-alphaDetails
In Materialize through 1.0.0, XSS is possible via the Toast feature.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/materialize-css
Introduced in:
0No fixed version published yet for materialize-css (npm). Pin to a known-safe version or switch to an alternative.
npm/@materializecss/materialize
Introduced in:
0Fixed in: 1.1.0-alphaFix
npm install @materializecss/materialize@1.1.0-alphaReferences
- https://nvd.nist.gov/vuln/detail/CVE-2019-11004[ADVISORY]
- https://github.com/Dogfalo/materialize/issues/6286[WEB]
- https://github.com/Dogfalo/materialize/issues/6331#issuecomment-549080183[WEB]
- https://github.com/materializecss/materialize/pull/49[WEB]
- https://github.com/samschurter/materialize/commit/3aae4cc9bb2b58c337bf25d2f04f129a2a0fa78f[WEB]
- https://github.com/Dogfalo/materialize[PACKAGE]
- https://github.com/advisories/GHSA-rg3q-jxmp-pvjj[ADVISORY]