MEDIUM5.4
GHSA-jj45-24rw-v6jw
Cross-site scripting in TotalJS
Quick fix
GHSA-jj45-24rw-v6jw — total4: upgrade to the fixed version with the command below.
npm install total4@0.0.81Details
A stored cross-site scripting (XSS) vulnerability in TotalJS allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field in the settings module.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-30094[ADVISORY]
- https://github.com/totaljs/flow/issues/100[WEB]
- https://github.com/totaljs/framework4/commit/e2cea690c3fe4453e94da896a69f832511f65179[WEB]
- https://github.com/totaljs/framework4[PACKAGE]
- https://www.edoardoottavianelli.it/CVE-2023-30094[WEB]
- https://www.youtube.com/watch?v=8VbTm2sIdBE[WEB]
- https://www.youtube.com/watch?v=vOb9Fyg3iVo[WEB]