SS-2016-015: XSS In OptionsetField and CheckboxSetField
List of key / value pairs assigned to OptionsetField
or CheckboxSetField
do not have a default casting assigned to them. The effect of this is a potential XSS vulnerability in lists where either key or value contain unescaped HTML.
References
Detect and mitigate SS-2016-015 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →