VDB
Sign up
MEDIUM4.8

GHSA-hfxp-j95j-cwrp

uvdesk/community-skeleton vulnerable to Stored Cross-site Scripting

Quick fix

GHSA-hfxp-j95j-cwrp — uvdesk/community-skeleton: upgrade to the fixed version with the command below.

composer require uvdesk/community-skeleton:^1.1.0

Details

Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/uvdesk/community-skeleton
Introduced in: 0Fixed in: 1.1.0
Fixcomposer require uvdesk/community-skeleton:^1.1.0

References