OSV 1.4.0 · github-reviewed · 修改于 2023-09-06 06:42
发布时间
2021-12-11 04:06
GitHub 审查时间
2021-05-26 04:08
NVD 发布时间
2020-04-23 00:15
源文件
advisories/github-reviewed/2021/12/GHSA-hg2p-2cvq-4ppv/GHSA-hg2p-2cvq-4ppv.json
lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams which can be abused to inject malicious JavaScript.