Description
Affected versions of fuelux
contain a cross-site scripting vulnerability in the Pillbox feature. By supplying a script as a value for a new pillbox, it is possible to cause arbitrary script execution.
Recommendation
Update the fuelux
package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.15.7
- Patched version(s): 3.15.7
References
Related Issues
- Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24772
- XSS vulnerability that affects bootstrap (GHSA-3mgp-fx93-9xv5) - CVE-2018-20676
- follow-redirects' Proxy-Authorization header kept across hosts - CVE-2024-28849
- Hidden fields can be leaked on readable collections in Payload - CVE-2023-30843
- Tags:
- npm
- fuelux
Anything's wrong? Let us know Last updated on January 11, 2023