VYPR

npm package

izimodal

pkg:npm/izimodal

Vulnerabilities (1)

  • CVE-2021-32860MedFeb 21, 2023
    affected < 1.6.1fixed 1.6.1

    iziModal is a modal plugin with jQuery. Versions prior to 1.6.1 are vulnerable to cross-site scripting (XSS) when handling untrusted modal titles. An attacker who is able to influence the field `title` when creating a `iziModal` instance is able to supply arbitrary `html` or `jav