PT-2022-17570 · Npm · @Yaireo/Tagify

Roman Rott

·

Published

2022-04-29

·

Updated

2022-09-23

·

CVE-2022-25854

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions @yaireo/tagify versions prior to 4.9.8
Description The issue affects the package used for rendering UI components inside input or text fields. An attacker can pass a malicious placeholder value to fire the cross-site scripting (XSS) payload.
Recommendations For versions prior to 4.9.8, update to version 4.9.8 or later to resolve the issue. As a temporary workaround, consider restricting the input of placeholder values to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-25854
GHSA-PXPF-V376-7XX5
SNYK-JS-YAIREOTAGIFY-2404358

Affected Products

@Yaireo/Tagify