CVE-2022-25873

The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vuetifyjs:vuetify:*:*:*:*:*:*:*:*
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta5:*:*:*:*:*:*
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta6:*:*:*:*:*:*
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta7:*:*:*:*:*:*
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta8:*:*:*:*:*:*
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta9:*:*:*:*:*:*

History

No history.

Information

Published : 2022-09-18 15:15

Updated : 2022-09-21 12:49


NVD link : CVE-2022-25873

Mitre link : CVE-2022-25873

CVE.ORG link : CVE-2022-25873


JSON object : View

Products Affected

vuetifyjs

  • vuetify
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')