OSV 1.4.0 · unreviewed · 修改于 2022-02-15 09:46
发布时间
2022-02-15 09:46
GitHub 审查时间
—
NVD 发布时间
2021-05-12 01:15
源文件
advisories/unreviewed/2022/02/GHSA-mpgq-6jmr-6c67/GHSA-mpgq-6jmr-6c67.json
The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website."
该公告没有提供结构化的受影响软件包信息。