Vulnerable Package issue exists @ Npm-jquery-3.2.1 in branch master
In jQuery versions before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Namespace: srcdevel1
Repository: dvja
Repository Url: https://github.com/srcdevel1/dvja
CxAST-Project: srcdevel1/dvja
CxAST platform scan: 275e3e87-21b4-460d-8d79-5eeebeb21604
Branch: master
Application: dvja
Severity: MEDIUM
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-79
Addition Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: NONE
References
Advisory
Release Note
Pull request
Commit
Advisory
Advisory
Vulnerable Package issue exists @ Npm-jquery-3.2.1 in branch master
In jQuery versions before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Namespace: srcdevel1
Repository: dvja
Repository Url: https://github.com/srcdevel1/dvja
CxAST-Project: srcdevel1/dvja
CxAST platform scan: 275e3e87-21b4-460d-8d79-5eeebeb21604
Branch: master
Application: dvja
Severity: MEDIUM
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-79
Addition Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: NONE
References
Advisory
Release Note
Pull request
Commit
Advisory
Advisory