Intel

AIKIDO-2024-10253

send is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2024-43799 Published Sep 11, 2024

45

Medium Risk

This Affects:

jssend
0.9.0 - 0.18.0
Fixed in 0.19.0
1.0.0 - 1.0.0
Fixed in 1.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Cross-site Scripting (XSS) via the redirect function due to improper sanitization of user input.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

send is vulnerable to Cross-site Scripting (XSS) in versions 0.9.0 - 0.18.0 and 1.0.0 - 1.0.0.

How to fix this

Upgrade the send library to the patch version.