Cross site scripting in Angular
Moderate severity
GitHub Reviewed
Published
Jun 18, 2020
to the GitHub Advisory Database
•
Updated Sep 8, 2023
Description
Reviewed
Jun 18, 2020
Published to the GitHub Advisory Database
Jun 18, 2020
Last updated
Sep 8, 2023
angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping
<option>
elements in<select>
ones changes parsing behavior, leading to possibly unsanitizing code.References