gettext.js has a Cross-site Scripting injection
High severity
GitHub Reviewed
Published
Aug 15, 2024
in
guillaumepotier/gettext.js
•
Updated Aug 16, 2024
Description
Published to the GitHub Advisory Database
Aug 15, 2024
Reviewed
Aug 15, 2024
Published by the National Vulnerability Database
Aug 16, 2024
Last updated
Aug 16, 2024
Impact
Possible vulnerability to XSS injection if .po dictionary definition files is corrupted
Patches
Update gettext.js to 2.0.3
Workarounds
Make sure you control the origin of the definition catalog to prevent the use of this flaw in the definition of plural forms.
References