Reflected Cross-Site Scripting in jquery.terminal
Moderate severity
GitHub Reviewed
Published
May 29, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
May 29, 2019
Published to the GitHub Advisory Database
May 29, 2019
Last updated
Jan 9, 2023
Versions of
jquery.terminal
prior to 1.21.0 are vulnerable to Reflected Cross-Site Scripting. If the application has either of the optionsanyLinks
orinvokeMethods
set to true, the application may execute arbitrary JavaScript through crafted malicious payloads due to insufficient sanitization.Recommendation
Upgrade to version 1.21.0 or later
References