Files
CVEs-PoC/2022/CVE-2022-25854.md
T
2024-06-18 02:51:15 +02:00

772 B

CVE-2022-25854

Description

This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the XSS payload.

POC

Reference

Github

No PoCs found on GitHub currently.