GHSA-hgr5-82rc-p936

Suggest an improvement
Source
https://github.com/advisories/GHSA-hgr5-82rc-p936
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-hgr5-82rc-p936/GHSA-hgr5-82rc-p936.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hgr5-82rc-p936
Published
2020-09-01T21:24:41Z
Modified
2020-08-31T18:34:23Z
Summary
Cross-Site Scripting in md-data-table
Details

All versions of md-data-table are vulnerable to cross-site scripting (XSS). This vulnerability is exploitable if an attacker has control over data that is rendered by mdt-row

Recommendation

As there is no fix for this vulnerability at this time we recommend either selecting another package to perform this functionality or properly sanitizing all user data prior to rendering with md-data-table

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-08-31T18:34:23Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / md-data-table

Package

Name
md-data-table
View open source insights on deps.dev
Purl
pkg:npm/md-data-table

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-hgr5-82rc-p936/GHSA-hgr5-82rc-p936.json"