VDB
Sign up
MEDIUM6.1

GHSA-3wf7-83q3-948c

Remote code execution in alextselegidis/easyappointments

Details

Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/alextselegidis/easyappointments
Introduced in: 0

No fixed version published yet for alextselegidis/easyappointments (composer). Pin to a known-safe version or switch to an alternative.

References