PT-2020-9608 · Google+2 · Angular+2

Igor Minar

·

Published

2019-11-18

·

Updated

2026-01-14

·

CVE-2019-14863

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions angular versions prior to 1.5.0-beta.0 angular versions prior to 1.5.0-beta.1
Description The issue allows attackers to execute arbitrary JavaScript in a victim's browser if the xlink:href attribute value is user-controlled, due to the package's failure to sanitize it. This can occur when the web application delivers data to its users along with other trusted dynamic content without validating it.
Recommendations For versions prior to 1.5.0-beta.0, upgrade to version 1.5.0-beta.1 or later. For versions prior to 1.5.0-beta.1, upgrade to version 1.5.0-beta.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-14863
DLA-1995-1
GHSA-R5FX-8R73-V86C
USN-7958-1

Affected Products

Linuxmint
Ubuntu
Angular