Vulnerabilities/

Baremetrics date range picker vulnerable to Cross-site Scripting

Severity:
Medium

Description

The Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender view. Versions 1.0.14 and prior are prone to cross-site scripting (XSS) when handling untrusted placeholder entries.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
baremetrics-calendar
Anything's wrong? Let us know Last updated on February 22, 2023