QID 980694
QID 980694: Nodejs (npm) Security Update for fuelux (GHSA-fwcw-5qw2-87mp)
Affected versions of `fuelux` contain a cross-site scripting vulnerability in the Pillbox feature. By supplying a script as a value for a new pillbox, it is possible to cause arbitrary script execution.
## Recommendation
Update to version 3.15.7 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fwcw-5qw2-87mp for updates pertaining to this vulnerability.
Vendor References
- GHSA-fwcw-5qw2-87mp -
github.com/advisories/GHSA-fwcw-5qw2-87mp
CVEs related to QID 980694
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fwcw-5qw2-87mp | fuelux |
|