QID 994853
Date Published: 2023-08-17
QID 994853: NodeJs (Npm) Security Update for svelecte (GHSA-7h45-grc5-89wq)
Svelecte item names are rendered as raw HTML with no escaping. This allows the injection of arbitrary HTML into the Svelecte dropdown. This can be exploited to execute arbitrary JavaScript whenever a Svelecte dropdown is opened.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-7h45-grc5-89wq for updates and patch information.
Vendor References
- GHSA-7h45-grc5-89wq -
github.com/advisories/GHSA-7h45-grc5-89wq
CVEs related to QID 994853
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7h45-grc5-89wq | svelecte |
|