CVE-2022-25873: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
The package vuetify from 2.0.0-beta.4 and before 2.6.10 is vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the ’eventName’ function within the VCalendar component.
References
- codepen.io/5v3n-08/pen/MWGKEjY
- github.com/advisories/GHSA-q4q5-c5cv-2p68
- github.com/vuetifyjs/vuetify/commit/ade1434927f55a0eccf3d54f900f24c5fa85a176
- github.com/vuetifyjs/vuetify/issues/15757
- nvd.nist.gov/vuln/detail/CVE-2022-25873
- security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBVUETIFYJS-3024407
- security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3024406
- security.snyk.io/vuln/SNYK-JS-VUETIFY-3019858
Detect and mitigate CVE-2022-25873 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →