Description
In Materialize through 1.0.0, XSS is possible via the Tooltip feature.
Remediation
References
https://github.com/Dogfalo/materialize/issues/6286
Related Vulnerabilities
CVE-2020-7673 Vulnerability in npm package node-extend
CVE-2021-33829 Vulnerability in npm package ckeditor4
CVE-2021-39134 Vulnerability in npm package @npmcli/arborist
CVE-2021-23329 Vulnerability in npm package nested-object-assign
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport