mobius1-selectr@2.3.4 vulnerabilities

A lightweight, dependency-free, mobile-friendly javascript select box replacement.

  • latest version

    2.4.13

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    5 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the mobius1-selectr package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    mobius1-selectr is a lightweight, dependency-free, mobile-friendly select box replacement written in vanilla javascript.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS). Multiple areas within the package including addTag,textContent,match and util elements writes user input to innerHTML allowing executing of JavaScript.

    How to fix Cross-site Scripting (XSS)?

    Upgrade mobius1-selectr to version 2.4.11 or higher.

    >=2.0.0 <2.4.11