GHSA-2hwp-g4g7-mwwj

Suggest an improvement
Source
https://github.com/advisories/GHSA-2hwp-g4g7-mwwj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/05/GHSA-2hwp-g4g7-mwwj/GHSA-2hwp-g4g7-mwwj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2hwp-g4g7-mwwj
Published
2019-05-29T20:25:35Z
Modified
2020-08-31T18:35:05Z
Summary
Reflected Cross-Site Scripting in jquery.terminal
Details

Versions of jquery.terminal prior to 1.21.0 are vulnerable to Reflected Cross-Site Scripting. If the application has either of the options anyLinks or invokeMethods set to true, the application may execute arbitrary JavaScript through crafted malicious payloads due to insufficient sanitization.

Recommendation

Upgrade to version 1.21.0 or later

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-05-29T20:24:48Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / jquery.terminal

Package

Name
jquery.terminal
View open source insights on deps.dev
Purl
pkg:npm/jquery.terminal

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.21.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/05/GHSA-2hwp-g4g7-mwwj/GHSA-2hwp-g4g7-mwwj.json"