Filtered by vendor Smartystreets Subscriptions
Filtered by product Liveaddressplugin.js Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-29455 1 Smartystreets 1 Liveaddressplugin.js 2024-08-04 6.1 Medium
A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressPlugin.js 3.2 allows remote attackers to inject arbitrary web script or HTML via any address parameter (e.g., street or country).