DOM-based XSS in gmail-js
High severity
GitHub Reviewed
Published
Sep 1, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 1, 2020
Last updated
Jan 9, 2023
Affected versions of
gmail-js
are vulnerable to cross-site scripting in thetools.parse_response
,helper.get.visible_emails_post
, andhelper.get.email_data_post
functions, which pass user input directly into the Function constructor.Recommendation
Update to version 0.6.5 or later.
References