Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgw5-rp4p-qhp6

Опубликовано: 28 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

quill-mention Cross-site Scripting vulnerability

Versions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, via the renderList function.

Note:

If the mentions list is sourced from unsafe (user-sourced) data, this might allow an injection attack when a Quill user hits @.

Пакеты

Наименование

quill-mention

npm
Затронутые версииВерсия исправления

< 4.0.0

4.0.0

EPSS

Процентиль: 79%
0.01237
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 2 лет назад

Versions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, via the renderList function. **Note:** If the mentions list is sourced from unsafe (user-sourced) data, this might allow an injection attack when a Quill user hits @.

EPSS

Процентиль: 79%
0.01237
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79