Cross-Site Scripting in emojione
High severity
GitHub Reviewed
Published
Sep 1, 2020
to the GitHub Advisory Database
•
Updated Mar 28, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 1, 2020
Last updated
Mar 28, 2023
Affected versions of
emojioneare vulnerable to cross-site scripting when user input is passed into thetoShort(),shortnameToImage(),unicodeToImage(), andtoImage()functions.Recommendation
Update to version 1.3.1 or later.
References