CVE-2021-3977

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in packagist/hillelcoren/invoice-ninja

Identifiers

GHSA-xg6r-5gx4-qxjm, CVE-2021-3977

Package Slug

packagist/hillelcoren/invoice-ninja

Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected Versions

All versions before 5.3.35

Solution

Upgrade to version 5.3.35 or above.

Last Modified

2022-01-11

source