Reflected cross-site scripting (XSS) In angular
Description
AngularJS Cross-site Scripting due to failure to sanitize xlink.href attributes
Versions of angular prior to 1.5.0-beta.1 are vulnerable to Cross-Site Scripting. The package fails to sanitize xlink:href attributes, which may allow attackers to execute arbitrary JavaScript in a victim's browser if the value is user-controlled.
Recommendation
Upgrade to version 1.5.0-beta.1 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 1.5.3-2 | ||
debian 12 | 1.5.3-2 | ||
npm | 1.5.0-beta.1 | ||
debian 11 | 1.5.3-2 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5.