Skip to content

vxe-table Cross-site Scripting vulnerability

Low severity GitHub Reviewed Published May 24, 2024 to the GitHub Advisory Database • Updated May 24, 2024

Package

npm vxe-table (npm)

Affected versions

< 3.7.10

Patched versions

3.7.10

Description

A vulnerability, which was classified as problematic, has been found in xuliangzhan vxe-table up to 3.7.9. This issue affects the function export of the file packages/textarea/src/textarea.js of the component vxe-textarea. The manipulation of the argument inputValue leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 3.7.10 is able to address this issue. The patch is named d70b0e089740b65a22c89c106ebc4627ac48a22d. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-266123.

References

Published by the National Vulnerability Database May 24, 2024
Published to the GitHub Advisory Database May 24, 2024
Reviewed May 24, 2024
Last updated May 24, 2024

Severity

Low
3.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Weaknesses

CVE ID

CVE-2023-1001

GHSA ID

GHSA-2qjp-fg8c-g878

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.