Loading HuntDB...

GHSA-h685-83w4-3ph3

GitHub Security Advisory

iziModal Cross-site Scripting vulnerability

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

iziModal is a modal plugin with jQuery. Versions prior to 1.6.1 are vulnerable to cross-site scripting (XSS) when handling untrusted modal titles. An attacker who is able to influence the field `title` when creating a `iziModal` instance is able to supply arbitrary `html` or `javascript` code that will be rendered in the context of a user, potentially leading to `XSS`. Version 1.6.1 contains a patch for this issue

Affected Packages

npm izimodal
Affected versions: 0 (fixed in 1.6.1)

Related CVEs

Key Information

GHSA ID
GHSA-h685-83w4-3ph3
Published
February 21, 2023 3:30 PM
Last Modified
February 22, 2023 12:10 AM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
izimodal
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 12, 2025 6:34 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.