Description
The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the ‘eventName’ function within the VCalendar component.
Recommendation
Update the vuetify package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.0.0-beta.4, < 2.6.10
- Patched version(s): 2.6.10
References
- GHSA-q4q5-c5cv-2p68
- codepen.io
- security.snyk.io
- CVE-2022-25873
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Reflected cross-site scripting (XSS) vulnerability - CVE-2022-0087
- Cross-site scripting vulnerability in TinyMCE alerts - CVE-2022-23494
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - CVE-2022-31175
- @dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details - CVE-2022-39350
You might also like:
- Tags:
- npm
- vuetify
Anything's wrong? Let us know Last updated on January 30, 2023


