Description
XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element.
Remediation
References
https://github.com/dollarshaveclub/shave/commit/da7371b0531ba14eae48ef1bb1456a3de4cfa954#diff-074799b511e4b61923dfd3f2a3bf9b54R67
https://github.com/dollarshaveclub/shave/compare/852b537...da7371b
https://www.npmjs.com/advisories/822
Related Vulnerabilities
CVE-2022-39381 Vulnerability in npm package muhammara
CVE-2016-10735 Vulnerability in maven package org.webjars.bower:bootstrap
CVE-2023-48711 Vulnerability in npm package google-translate-api-browser
CVE-2022-24697 Vulnerability in maven package org.apache.kylin:kylin-core-common
CVE-2021-41251 Vulnerability in npm package @sap-cloud-sdk/core