@claviska/jquery-minicolors vulnerable to Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
Feb 21, 2023
to the GitHub Advisory Database
•
Updated Jun 12, 2023
Description
Published by the National Vulnerability Database
Feb 20, 2023
Published to the GitHub Advisory Database
Feb 21, 2023
Reviewed
Feb 22, 2023
Last updated
Jun 12, 2023
jQuery MiniColors is a color picker built on jQuery. Prior to version 2.3.6, jQuery MiniColors is prone to cross-site scripting when handling untrusted color names. This issue is patched in version 2.3.6.
References