Cross-Site Scripting in vant
High severity
GitHub Reviewed
Published
Nov 22, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Nov 21, 2019
Published to the GitHub Advisory Database
Nov 22, 2019
Last updated
Jan 9, 2023
Versions of
vantprior to 2.1.8 are vulnerable to Cross-Site Scripting. The text value of thePickercomponent column is not sanitized, which may allow attackers to execute arbitrary JavaScript in a victim's browser.Recommendation
Upgrade to version 2.1.8 or later.
References