org.sakaiproject.rubrics:rubrics-service-impl@20.4

  • latest version

    22.0

  • first published

    7 years ago

  • latest version published

    4 years ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.sakaiproject.rubrics:rubrics-service-impl package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in ConversationsServiceImpl, whose saveTopic(), savePost(), and saveComment() methods persist the submitted message field without passing it through FormattedText.processFormattedText(), while the frontend renders those stored values with LitElement's unsafeHTML() directive in SakaiTopic.js, SakaiPost.js, and SakaiComment.js. A user with membership of a site can execute JavaScript in another member's browser, reaching that member's session and whatever the application grants it, by submitting HTML in a topic message, reply, or comment through the REST API. This requires an authenticated account in a site with the Conversations tool enabled and a target who views the content, and because the payload is stored it runs for every member who opens that topic until the record is removed.

    How to fix Cross-site Scripting (XSS)?

    A fix was pushed into the master branch but not yet published.

    [0,)