VDB
EN
HIGH 7.3

GHSA-vv3x-j2x5-36jc

Filament Unvalidated Range and Values summarizer values can be used for XSS

상세

Two Table summarizers (`Range`, `Values`) render raw database values without escaping HTML. If there is a lack of validation for the data in the columns that use these summarizers, an attacker could plant malicious HTML / JavaScript and achieve stored XSS that executes for users who view the table with those summarizers.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Packagist / filament/tables
최초 영향 버전: 4.0.0 수정 버전: 4.8.5
수정 composer require filament/tables:^4.8.5
Packagist / filament/tables
최초 영향 버전: 5.0.0 수정 버전: 5.3.5
수정 composer require filament/tables:^5.3.5

참고