QID 981281
QID 981281: Nodejs (npm) Security Update for yapi-vendor (GHSA-5xgh-643p-cp2g)
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5xgh-643p-cp2g for updates pertaining to this vulnerability.
Vendor References
- GHSA-5xgh-643p-cp2g -
github.com/advisories/GHSA-5xgh-643p-cp2g
CVEs related to QID 981281
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5xgh-643p-cp2g | yapi-vendor |
|