ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://spring.io/blog/2016/01/28/angularjs-escaping-the-expression-sandbox-for-xss | third party advisory exploit technical description |
https://nodesecurity.io/advisories/327 | third party advisory broken link |
https://github.com/ceolter/ag-grid/issues/1287 | third party advisory issue tracking |