zeroclipboard@1.1.7 vulnerabilities

The ZeroClipboard library provides an easy way to copy text to the clipboard using an invisible Adobe Flash movie and a JavaScript interface

Direct Vulnerabilities

Known vulnerabilities in the zeroclipboard package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
Cross-site Scripting (XSS)

zeroclipboard Affected versions of the package are vulnerable to Cross-site Scripting (XSS). This allows remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF query parameters.

How to fix Cross-site Scripting (XSS)?

Upgrade zeroclipboard to version 1.3.2 or higher.

>=1.0.7 <1.3.2