Описание
Cross site scripting in Metro UI
Metro UI v4.4.0 to v4.5.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function. User input is not properly sanitized before rendering in the textarea component.
Пакеты
Наименование
metro4
npm
Затронутые версииВерсия исправления
>= 4.4.0, <= 4.5.1
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
больше 3 лет назад
Metro UI v4.4.0 to v4.5.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function.