Description
Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.
Remediation
References
Related Vulnerabilities
WordPress Plugin Flickr Justified Gallery Cross-Site Scripting (3.3.6)
WordPress Plugin Event Registration 'event_id' Parameter SQL Injection (5.44)
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30179)
WordPress Plugin WP Marketplace TimThumb Arbitrary File Upload (1.1.0)