Intel

AIKIDO-2024-10126

magnific-popup is vulnerable to Cross-Site Scripting

Cross-Site Scripting Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 13, 2024

40

Medium Risk

This Affects:

JSmagnific-popup
0.9.6 - 1.1.0
Fixed in 1.2.0
Are you affected? Scan for Free

TL;DR

Affected versions of magnific-popup are vulnerable to Cross-site Scripting (XSS) if users are allowed to include (limited) HTML content (from editors like CKEditor) in the pop-up.

Who does this affect?

You are affected if you use a vulnerable version of magnific-popup and allow limited HTML content (from editors like CKEditor) in the pop-up.

Background info

magnific-popup is vulnerable to Cross-Site Scripting in versions 0.9.6 - 1.1.0.

How to fix this

Upgrade magnific-popup to a patch version.