Description
angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.
Remediation
References
Related Vulnerabilities
WordPress Plugin Wordpress Countdown Widget Cross-Site Scripting (3.1.9.2)
Drupal Insufficient Verification of Data Authenticity Vulnerability (CVE-2016-9450)
Atlassian Jira Incorrect Authorization Vulnerability (CVE-2018-20826)
WordPress Plugin Official MailerLite Sign Up Forms SQL Injection (1.4.3)