VDB
Sign up
MEDIUM5.4

GHSA-rcvr-8whx-3m5p

Layui cross-site scripting (XSS) vulnerability

Quick fix

GHSA-rcvr-8whx-3m5p — layui: upgrade to the fixed version with the command below.

npm install layui@2.7.5

Details

layui up to v2.74 was discovered to contain a cross-site scripting (XSS) vulnerability via the data-content parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/layui
Introduced in: 0Fixed in: 2.7.5
Fixnpm install layui@2.7.5

References