mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-14 23:28:04 +02:00
868 B
868 B
CVE-2022-25873
Description
The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.
POC
Reference
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBVUETIFYJS-3024407
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3024406
- https://security.snyk.io/vuln/SNYK-JS-VUETIFY-3019858
Github
No PoCs found on GitHub currently.