MEDIUM 6.1 npm
Cross-site scripting in jspdf
GHSA-3q6f-8grx-pr4v · CVE-2020-7691
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
It's possible to use nested script tags in order to bypass the filtering regex.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2020-7691
- WEB https://github.com/MrRio/jsPDF/issues/2971
- WEB https://github.com/MrRio/jsPDF/commit/d0323215b1a1cd1c35bf2b213274ae1e4797715d
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-575255
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-575253
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBMRRIO-575254
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-575252
- WEB https://snyk.io/vuln/SNYK-JS-JSPDF-568273
Ready to move
Start Securing
Free, no credit card | First findings in minutes