QID 981662
QID 981662: Nodejs (npm) Security Update for selectize-plugin-a11y (GHSA-8cpw-73f2-w58m)
Versions of `selectize-plugin-a11y ` prior to 1.1.0 are vulnerable to Cross-Site Scripting. The `accessibility.liveRegion.speak` function does not sanitize the `msg` variable before rendering it as HTML. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim's browser.
## Recommendation
Upgrade to version 1.1.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8cpw-73f2-w58m for updates pertaining to this vulnerability.
Vendor References
- GHSA-8cpw-73f2-w58m -
github.com/advisories/GHSA-8cpw-73f2-w58m
CVEs related to QID 981662
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8cpw-73f2-w58m | selectize-plugin-a11y |
|