Vulnerabilities (CVE)

Filtered by vendor Smartystreets Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-29455 1 Smartystreets 1 Liveaddressplugin.js 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressPlugin.js 3.2 allows remote attackers to inject arbitrary web script or HTML via any address parameter (e.g., street or country).