VDB
Sign up
MEDIUM6.4

GHSA-vggc-6pg2-xvp9

Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling

Details

Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers to inject malicious scripts. Remote attackers can inject XSS payloads through comments to execute arbitrary JavaScript in victims' browsers.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/vulnogram
Introduced in: 0

No fixed version published yet for vulnogram (npm). Pin to a known-safe version or switch to an alternative.

References