PT-2019-20034 · Vant · Vant

Published

2019-11-22

·

Updated

2019-11-22

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions vant versions prior to 2.1.8
Description The issue affects the Picker component, where the text value of its column is not properly sanitized. This could allow attackers to execute arbitrary JavaScript in a victim's browser, leading to a Cross-Site Scripting attack.
Recommendations Upgrade to version 2.1.8 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-9XR8-8HMC-389F

Affected Products

Vant