Reflected cross-site scripting (XSS) In ngx-bootstrap
Description
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to the search and highlight functionality within the typeahead component not escaping special characters.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version |
|---|---|---|
npm |
Aliases
1.
References
1.