Reflected cross-site scripting (XSS) In angular
Description
Angular (deprecated package) Cross-site Scripting
All versions of package angular are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.
NPM package angular is deprecated. Those who want to receive security updates should use the actively maintained package @angular/core.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version |
|---|---|---|
npm | ||
debian 11 | ||
debian 12 | ||
debian 13 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.