CVE-2022-25869

MEDIUM6.1EPSS 4.3%

Angular (deprecated package) Cross-site Scripting

Published: 7/16/2022Modified: 2/4/2026
Also known as:GHSA-prc3-vjfx-vhm9CGA-vrq8-v55v-jpvp

Description

All versions of package angular are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of `<textarea>` elements. NPM package [angular](https://www.npmjs.com/package/angular) is deprecated. Those who want to receive security updates should use the actively maintained package [@angular/core](https://www.npmjs.com/package/@angular/core).

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (15)