Angular.expression.injection.XSS.vulnerability

description-logoDescription

ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
It is possible to escape expression sandboxing and inject code that can break the application.

affected-products-logoAffected Products

ag-grid since #913

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary script code in the context of the affected application.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.

Version Updates

Date Version Detail
2023-01-03 0.00338

CVE References

CVE-2017-16009