Description
Toast UI Grid is a component to display and edit data. Versions prior to 4.21.3 are vulnerable to cross-site scripting attacks when pasting specially crafted content into editable cells. This issue was fixed in version 4.21.3. There are no known workarounds.
Recommendation
Update the tui-grid package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.21.3
- Patched version(s): 4.21.3
References
Related Issues
- Jodit Editor vulnerable to Cross-site Scripting (GHSA-42hx-vrxx-5r6v) - CVE-2022-23461
- materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input - CVE-2022-25349
- @dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details - CVE-2022-39350
- Joplin Desktop App vulnerable to Cross-site Scripting - CVE-2022-45598
- Tags:
- npm
- tui-grid
Anything's wrong? Let us know Last updated on January 31, 2023