MEDIUM5.4
GHSA-5xgh-643p-cp2g
Cross-site Scripting in yapi-vendor
Quick fix
GHSA-5xgh-643p-cp2g — yapi-vendor: upgrade to the fixed version with the command below.
npm install yapi-vendor@1.3.23Details
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.
Are you affected?
Enter the version of the package you're using.