CVE-2022-25873

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
18/09/2022
Last modified:
21/09/2022

Description

The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vuetifyjs:vuetify:*:*:*:*:*:*:*:* 2.0.1 (including) 2.6.10 (excluding)
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta5:*:*:*:*:*:*
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta6:*:*:*:*:*:*
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta7:*:*:*:*:*:*
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta8:*:*:*:*:*:*
cpe:2.3:a:vuetifyjs:vuetify:2.0.0:beta9:*:*:*:*:*:*