VDB
Sign up
HIGH

GHSA-crfx-5phg-hmw9

Cross-Site Scripting in ids-enterprise

Quick fix

GHSA-crfx-5phg-hmw9 — ids-enterprise: upgrade to the fixed version with the command below.

npm install ids-enterprise@4.18.2

Details

Versions of `ids-enterprise` prior to 4.18.2 are vulnerable to Cross-Site Scripting (XSS). Script tags in the `soho-autocomplete` component are not properly encoded and may allow attackers to execute arbitrary JavaScript.

## Recommendation

Upgrade to version 4.18.2 or later

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ids-enterprise
Introduced in: 0Fixed in: 4.18.2
Fixnpm install ids-enterprise@4.18.2

References