MEDIUM 6.1 npm
Cross-site scripting in jspdf
GHSA-vh59-v9r5-4mh4 · CVE-2020-7690 · SNYK-JS-JSPDF-575256
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Affected versions of this package are vulnerable to Cross-site Scripting (XSS). It's possible to inject JavaScript code via the html method.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2020-7690
- WEB https://github.com/MrRio/jsPDF/issues/2795
- WEB https://github.com/parallax/jsPDF/issues/2862
- WEB https://github.com/parallax/jsPDF/issues/2971
- WEB https://github.com/parallax/jsPDF/pull/2806
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-575260
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-575258
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBMRRIO-575259
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-575257
- WEB https://snyk.io/vuln/SNYK-JS-JSPDF-575256
Ready to move
Start Securing
Free, no credit card | First findings in minutes