CVE-2020-29455
11.12.2020, 20:15
A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressPlugin.js 3.2 allows remote attackers to inject arbitrary web script or HTML via any address parameter (e.g., street or country).
| Vendor | Product | Version |
|---|---|---|
| smartystreets | liveaddressplugin.js | 3.2 |
𝑥
= Vulnerable software versions
References