Description
The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the ‘eventName’ function within the VCalendar component.
Recommendation
Update the vuetify package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.0.0-beta.4, < 2.6.10
- Patched version(s): 2.6.10
References
Could your website be exposed too?
SmartScanner can check your website for Vuetify Cross-site Scripting vulnerability and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Reflected cross-site scripting (XSS) vulnerability - CVE-2022-0087
- Cross-site scripting vulnerability in TinyMCE alerts - CVE-2022-23494
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - CVE-2022-31175
- @dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details - CVE-2022-39350
You might also like:
See something that needs correcting? Let us knowUpdated January 30, 2023


