icon

We found results for “

CVE-2021-32860

Good to know:

icon
icon

Date: February 19, 2023

iziModal is a modal plugin with jQuery. Versions prior to 1.6.1 are vulnerable to cross-site scripting (XSS) when handling untrusted modal titles. An attacker who is able to influence the field "title" when creating a "iziModal" instance is able to supply arbitrary "html" or "javascript" code that will be rendered in the context of a user, potentially leading to "XSS". Version 1.6.1 contains a patch for this issue

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version izimodal - 1.6.1;izimodal - 1.6.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us