MEDIUM6.1
GHSA-r4hg-4cpq-q57c
jSuites subect to Cross-site Scripting
Quick fix
GHSA-r4hg-4cpq-q57c — jsuites: upgrade to the fixed version with the command below.
npm install jsuites@5.0.1Details
Versions of the package jsuites before 5.0.1 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization in the Editor() function.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25979[ADVISORY]
- https://github.com/jsuites/jsuites/issues/134[WEB]
- https://github.com/jsuites/jsuites/commit/b31770d5fe91684a00177f629aab933139c32d9f[WEB]
- https://github.com/jsuites/jsuites[PACKAGE]
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3253331[WEB]
- https://security.snyk.io/vuln/SNYK-JS-JSUITES-3226764[WEB]