Description
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Remediation
References
Related Vulnerabilities
WordPress Plugin Apptivo eCommerce Multiple Cross-Site Scripting Vulnerabilities (1.1.5)
WordPress Improper Input Validation Vulnerability (CVE-2017-9065)
WebLogic CVE-2020-14859 Vulnerability (CVE-2020-14859)
PHP NULL Pointer Dereference Vulnerability (CVE-2018-19395)
WordPress Plugin MailPoet Newsletters (Previous) Multiple Unspecified Vulnerabilities (2.7.1)