VDB
Sign up
MEDIUM5.4

GHSA-5xgh-643p-cp2g

Cross-site Scripting in yapi-vendor

Quick fix

GHSA-5xgh-643p-cp2g — yapi-vendor: upgrade to the fixed version with the command below.

npm install yapi-vendor@1.3.23

Details

An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/yapi-vendor
Introduced in: 0Fixed in: 1.3.23
Fixnpm install yapi-vendor@1.3.23

References