CVE-2024-9440 - Slim Select Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-9440 Published : Oct. 2, 2024, 7:15 p.m. | 1 hour, 59 minutes ago Description : Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is assigned to an innerHTML without sanitation. Software that depends on this library to dynamically generate lists using unsanitized user-provided input may be vulnerable to cross-site scripting, resulting in attacker executed JavaScript. At this time, no patch is available. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Okt 2, 2024 - 23:15
 0  3
CVE-2024-9440 - Slim Select Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-9440
Published : Oct. 2, 2024, 7:15 p.m. | 1 hour, 59 minutes ago
Description : Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is assigned to an innerHTML without sanitation. Software that depends on this library to dynamically generate lists using unsanitized user-provided input may be vulnerable to cross-site scripting, resulting in attacker executed JavaScript. At this time, no patch is available.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...