VDB
Sign up
HIGH

GHSA-hpfq-8wx8-cgqw

Cross-Site Scripting in ids-enterprise

Quick fix

GHSA-hpfq-8wx8-cgqw — ids-enterprise: upgrade to the fixed version with the command below.

npm install ids-enterprise@4.18.2

Details

Versions of `ids-enterprise` prior to 4.18.2 are vulnerable to Cross-Site Scripting (XSS). The `modal` component fails to sanitize input to the `title` attribute, which may allow attackers to execute arbitrary JavaScript.

## Recommendation

Upgrade to version 4.18.2 or later

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ids-enterprise
Introduced in: 0Fixed in: 4.18.2
Fixnpm install ids-enterprise@4.18.2

References