GMS-2019-65: Cross-Site Scripting in vant
(updated )
Versions of vant
are vulnerable to Cross-Site Scripting. The text value of the Picker
component column is not sanitized, which may allow attackers to execute arbitrary JavaScript in a victim’s browser. Upgrade to or later.
References
Detect and mitigate GMS-2019-65 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →