Description
In Materialize through 1.0.0, XSS is possible via the Tooltip feature.
Remediation
References
https://github.com/Dogfalo/materialize/issues/6286
Related Vulnerabilities
CVE-2021-23413 Vulnerability in npm package jszip
CVE-2020-16040 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-23337 Vulnerability in maven package org.webjars.npm:lodash
CVE-2019-16869 Vulnerability in maven package io.netty:netty-all
CVE-2021-42340 Vulnerability in maven package org.apache.tomcat:tomcat-websocket