Vulnerabilities/

Cross-Site Scripting in ids-enterprise

Severity:
High

Description

Versions of ids-enterprise prior to 4.18.2 are vulnerable to Cross-Site Scripting (XSS). The soho-dropdown component does not properly encode its output and may allow attackers to execute arbitrary JavaScript.

Recommendation

Update the ids-enterprise package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ids-enterprise
Anything's wrong? Let us know Last updated on January 09, 2023