5.4
CVSSv3

CVE-2022-25349

Published: 01/05/2022 Updated: 11/05/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

materializecss materialize

Vendor Advisories

Debian Bug report logs - #1014727 materialize: CVE-2022-25349 Package: src:materialize; Maintainer for src:materialize is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sun, 10 Jul 2022 21:39:01 UTC Severity: normal Tags: security ...