OSV 1.4.0 · github-reviewed · 修改于 2021-10-05 04:36
发布时间
2020-09-05 01:21
GitHub 审查时间
2020-09-01 02:59
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-whv6-rj84-2vh2/GHSA-whv6-rj84-2vh2.json
Versions of nextcloud-vue-collections prior to 0.4.2 are vulnerable to Cross-Site Scripting (XSS). The v-tooltip component has an insecure defaultHTML configuration that allows arbitrary JavaScript to be injected in the tooltip of a collection item. This allows attackers to execute arbitrary code in a victim's browser.
Upgrade to version 0.4.2 or later.