Vulnerabilities/

Cross-Site Scripting in yui

Severity:
Medium

Description

Affected versions of yui are vulnerable to cross-site scripting in the uploader.swf and io.swf utilities, via script injection in the url.

Recommendation

Update the yui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
yui
Anything's wrong? Let us know Last updated on January 09, 2023