Vulnerabilities/

Vuetify Cross-site Scripting vulnerability

Severity:
Medium

Description

The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the ‘eventName’ function within the VCalendar component.

Recommendation

Update the vuetify package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vuetify
Anything's wrong? Let us know Last updated on January 30, 2023