GMS-2019-36: Reflected Cross-Site Scripting in jquery.terminal
(updated )
Versions of jquery.terminal
are vulnerable to Reflected Cross-Site Scripting. If the application has either of the options anyLinks
or invokeMethods
set to true, the application may execute arbitrary JavaScript through crafted malicious payloads due to insufficient sanitization.
References
Detect and mitigate GMS-2019-36 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →