logo

Database

Reflected cross-site scripting (XSS) In angular

Description

AngularJS Cross-site Scripting due to failure to sanitize xlink.href attributes Versions of angular prior to 1.5.0-beta.1 are vulnerable to Cross-Site Scripting. The package fails to sanitize xlink:href attributes, which may allow attackers to execute arbitrary JavaScript in a victim's browser if the value is user-controlled.

Recommendation

Upgrade to version 1.5.0-beta.1 or later.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions