Executive brief
angular-ui-notification is a JavaScript library used to display notifications in Angular web applications. The library fails to sanitize user-supplied input before rendering it, allowing attackers to inject malicious scripts that execute in the browser and steal session tokens, credentials, or manipulate page content for users viewing the application.
Technical details
The vulnerability is a stored/reflected cross-site scripting (XSS) flaw caused by insufficient input sanitization in the notification message handler. Affected versions (0.1.0, 0.2.0, 0.3.6) directly render user-supplied message parameters without HTML encoding or context-aware escaping. An attacker can pass a crafted message containing script tags (e.g., <script>alert(1)</script>) to the notification function. When rendered by the library, the script executes with the privileges of the authenticated user in the same security context as the application. No authentication or special preconditions are required if the application passes untrusted user input directly to the notification library. The project is no longer actively maintained.
Affected products
- angular-ui-notification angular-ui-notification 0.1.0 through 0.3.6
Timeline
- 2023-06-30: disclosed
- 2023-06-30: advisory: CVE-2023-34840 published