In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.
Start learningUpgrade hapi
to version 0.16.0 or higher, although later versions are also susceptible to vulnerabilities. Last known safe version is 11.1.4.
hapi
is an HTTP Server framework.
Affected versions of the package are vulnerable to Cross-site Scripting (XSS). They do not handle invalid payloads, allowing attackers craft malicious links or create a third party web page to inject code into the browser.
The fix was introduced in version 0.16.0 by parsing the payload and verifying its validity.
<>