Description
Affected versions of fuelux contain a cross-site scripting vulnerability in the Pillbox feature. By supplying a script as a value for a new pillbox, it is possible to cause arbitrary script execution.
Recommendation
Update the fuelux package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.15.7
- Patched version(s): 3.15.7
References
Related Issues
- jQuery-UI vulnerable to Cross-site Scripting in dialog closeText - CVE-2016-7103
- Bootstrap Cross-site Scripting vulnerability - CVE-2016-10735
- Bootstrap Cross-site Scripting vulnerability (GHSA-4p24-vmcr-4gqj) - CVE-2016-10735
- Bootstrap Vulnerable to Cross-Site Scripting - CVE-2019-8331
- Tags:
- npm
- fuelux
Anything's wrong? Let us know Last updated on January 11, 2023