Xuliangzhan · Vxe-Table · CVE-2023-1001
**Name of the Vulnerable Software and Affected Versions**
xuliangzhan vxe-table versions up to 3.7.9
**Description**
A problematic issue has been found in the function export of the file packages/textarea/src/textarea.js of the component vxe-textarea. The manipulation of the argument `inputValue` leads to cross-site scripting. The attack may be initiated remotely.
**Recommendations**
For versions up to 3.7.9, upgrade to version 3.7.10 to address this issue. As a temporary workaround, consider restricting the use of the `inputValue` argument in the affected component until the upgrade is applied.