@meshconnect/web-link-sdk@3.3.0 vulnerabilities

A client-side JS library for integrating with Mesh Connect

  • latest version

    3.3.4

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    2 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @meshconnect/web-link-sdk package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    @meshconnect/web-link-sdk is an A client-side JS library for integrating with Mesh Connect

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the createLink.openLink() function. An attacker can execute arbitrary JavaScript code in the context of the parent page by supplying a specially crafted base64-encoded payload that, when decoded, sets a malicious URL as the src attribute of an iframe. This can allow access to the parent page's DOM, storage, session, and cookies, and may enable hijacking of existing iframes if a custom iframe ID is specified.

    How to fix Cross-site Scripting (XSS)?

    Upgrade @meshconnect/web-link-sdk to version 3.3.2 or higher.

    <3.3.2