Cross-Site Scripting in jqtree
High severity
GitHub Reviewed
Published
Sep 1, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 1, 2020
Last updated
Jan 9, 2023
Affected versions of
jqtreeare vulnerable to cross-site scripting in the drag and drop functionality for modifying tree data.When a user attempts to drag a node to a different position in the hierarchy, script content existing within the node will be executed.
Recommendation
Update to 1.3.4 or later.
References