All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published:

Updated: 2024-09-17T00:55:44.827Z

Reserved: 2022-02-24T00:00:00

Link: CVE-2022-25349

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-01T16:15:08.483

Modified: 2024-11-21T06:52:03.290

Link: CVE-2022-25349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.