GHSA-r3xc-47qg-h929
UNKNOWNVersions of @ionic/core prior to 4.0.3, 4.1.3, 4.2.1 or 4.3.1 are vulnerable to Cross-Site Scripting (XSS). The package uses the unsafe innerHTML function without sanitizing input, which may allow attackers to execute arbitrary JavaScript on the victim's browser. This issue affects the components:
- Affected
- >=0, <4.0.3, >=4.1.0, <4.1.3, >=4.2.0, <4.2.1, >=4.3.0, <4.3.1
- Fixed in
- not stated
- Weakness
- CWE-79
- Published
- 2020-09-03
- Source
- osv