Executive brief
fullpage.js is a popular JavaScript library used to create fullscreen scrolling websites. The library fails to sanitize URL values in anchor tag href attributes, allowing attackers to inject malicious JavaScript code that executes in users' browsers. An attacker with the ability to control anchor tag content could steal session tokens, capture user inputs, or redirect users to phishing sites.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in fullpage.js stemming from insufficient input sanitization of href attributes in dynamically created anchor elements. The library does not properly validate or escape user-supplied URLs before inserting them into the DOM, allowing an attacker to break out of the href context and inject arbitrary HTML or JavaScript. The attack requires user interaction (clicking the link) and authenticated access to control anchor tag creation, or the ability to supply content to a page using the library. The vulnerability was fixed in version 4.0.5 via proper URL sanitization.
Affected products
- Alvaro Trigo fullpage.js before 4.0.5
Timeline
- 2022-04-12: disclosed
- 2022-04-13: patched: Fixed in version 4.0.5