VDB
Sign up
MEDIUM6.1

GHSA-qc2p-6qrf-25j2

laracom Cross-site Scripting

Quick fix

GHSA-qc2p-6qrf-25j2 — jsdecena/laracom: upgrade to the fixed version with the command below.

composer require jsdecena/laracom:^1.5.0

Details

laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has a Cross-site Scripting vulnerability via search query.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/jsdecena/laracom
Introduced in: 1.4.11Fixed in: 1.5.0
Fixcomposer require jsdecena/laracom:^1.5.0

References