Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rf66-hmqf-q3fc

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Improper Neutralization of Input During Web Page Generation in Select2

In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.

Пакеты

Наименование

select2

npm
Затронутые версииВерсия исправления

< 4.0.6

4.0.6

EPSS

Процентиль: 59%
0.00373
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.3
redhat
почти 7 лет назад

In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.

CVSS3: 6.1
nvd
почти 7 лет назад

In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.

CVSS3: 6.1
debian
почти 7 лет назад

In Select2 through 4.0.5, as used in Snipe-IT and other products, rich ...

EPSS

Процентиль: 59%
0.00373
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79