angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.
| Software | From | Fixed in |
|---|---|---|
@schematics / angular
|
- | 1.8.0 |
| angularjs / angularjs | - | 1.8.0 |