Description
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Remediation
References
Related Vulnerabilities
PHPFusion Code Execution Vulnerability (CVE-2019-12099)
WordPress Plugin Contact Form 7 Multi-Step Forms Security Bypass (3.0.8)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2006-0369)
Joomla! Core Multiple Cross-Site Scripting Vulnerabilities (2.5.0 - 3.9.1)
WordPress Plugin Relevanssi-A Better Search Cross-Site Scripting (4.0.4)