
Cloud Vulnerability DB
A community-led vulnerabilities database
A high-severity Cross-Site Scripting (XSS) vulnerability was identified in the md-data-table npm package, tracked as GHSA-hgr5-82rc-p936. The vulnerability was published to the GitHub Advisory Database on September 1, 2020, and was last updated on January 9, 2023. The vulnerability affects all versions of md-data-table (>= 0.0.0) with no patched versions available (GitHub Advisory).
The vulnerability is classified as CWE-79 (Cross-Site Scripting) and has been assessed as high severity. The security flaw specifically manifests when an attacker has control over data that is rendered by the mdt-row component (GitHub Advisory).
The vulnerability allows for Cross-Site Scripting attacks when malicious data is processed through the mdt-row component, potentially enabling attackers to execute arbitrary JavaScript code in the context of the affected application (GitHub Advisory).
The vulnerability is exploitable when an attacker can control the data that is rendered by the mdt-row component in the md-data-table package (GitHub Advisory).
Since there is no official fix available for this vulnerability, users are recommended to either switch to an alternative package that provides similar functionality or implement proper sanitization of all user data before rendering it with md-data-table (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."