PT-2020-21540 · None · Lazysizes

Published

2020-09-03

·

Updated

2020-09-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions lazysizes versions prior to 5.2.1-rc1
Description The issue affects the video-embed plugin of lazysizes, which fails to properly sanitize certain attributes, including data-vimeo, data-vimeoparams, data-youtube, and data-ytparams. This oversight allows attackers to execute arbitrary JavaScript code in a victim's browser if they have control over these vulnerable attributes.
Recommendations Upgrade to version 5.2.1-rc1 or later.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-W4VP-3MQ7-7V82

Affected Products

Lazysizes