Cross-Site Scripting in vant
High severity
GitHub Reviewed
Published
Nov 22, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Nov 21, 2019
Published to the GitHub Advisory Database
Nov 22, 2019
Last updated
Jan 9, 2023
Versions of
vant
prior to 2.1.8 are vulnerable to Cross-Site Scripting. The text value of thePicker
component column is not sanitized, which may allow attackers to execute arbitrary JavaScript in a victim's browser.Recommendation
Upgrade to version 2.1.8 or later.
References