HIGH
GHSA-49r3-3h96-rwj6
Cross-Site Scripting in ids-enterprise
Quick fix
GHSA-49r3-3h96-rwj6 — ids-enterprise: upgrade to the fixed version with the command below.
npm install ids-enterprise@4.18.2Details
Versions of `ids-enterprise` prior to 4.18.2 are vulnerable to Cross-Site Scripting (XSS). The `soho-dropdown` component does not properly encode its output and may allow attackers to execute arbitrary JavaScript.
## Recommendation
Upgrade to version 4.18.2 or later
Are you affected?
Enter the version of the package you're using.