ngx-extended-pdf-viewer is vulnerable to Cross-site Scripting (XSS)
20
Low Risk
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) if the unsafe-inline rule is used in the content-security-policy (CSP) meta tag. The unsafe-inline keyword undermines most of the security benefits provided by CSP. It was required in order to enable certain functionality of the package.
You are affected if you are using a version of this package = 19.4.1 and 'unsafe-inline' is used in the content-security-policy meta tag.
ngx-extended-pdf-viewer is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 19.4.1.
Upgrade the ngx-extended-pdf-viewer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant