mageplaza/magento-2-social-login is vulnerable to Cross-site Scripting (XSS)
60
Medium Risk
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to insufficient input sanitization in the $message variable, which is rendered within the div element for error messages. An attacker can exploit this flaw by injecting malicious JavaScript code into the $message parameter, which will then be executed in the context of a victim's browser when the error message is displayed. It could lead to session hijacking, defacement, or other client-side attacks.
You are affected if you are using a version that falls within the vulnerable range.
mageplaza/magento-2-social-login is vulnerable to Cross-site Scripting (XSS) in versions 4.0.0 - 4.1.17.
Upgrade the mageplaza/magento-2-social-login library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant