MEDIUM4.8
GHSA-hfxp-j95j-cwrp
uvdesk/community-skeleton vulnerable to Stored Cross-site Scripting
Quick fix
GHSA-hfxp-j95j-cwrp — uvdesk/community-skeleton: upgrade to the fixed version with the command below.
composer require uvdesk/community-skeleton:^1.1.0Details
Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/uvdesk/community-skeleton
Introduced in:
0Fixed in: 1.1.0Fix
composer require uvdesk/community-skeleton:^1.1.0