Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-41924: fixed broken access control issue for account update by naresh-webkul · Pull Request #195 · krayin/laravel-crm

Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).

CVE
#xss#web#js#git

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

        • ui.js
      • mix-manifest.json
      • table-body.vue

Prev Next

fixed xss issue at datagrid

  • Loading branch information

commit 882dc2e7e7e9149b96cf1ccacf34900960b92fb7

Large diffs are not rendered by default.

@@ -1,5 +1,5 @@

{

"/js/ui.js": "/js/ui.js?id=04e2fdebe8621c6953e2",

"/js/ui.js": "/js/ui.js?id=42bdc4ac52e1762101c3",

"/css/ui.css": "/css/ui.css?id=58acb02c87af96127d4b",

"/images/add-icon.svg": "/images/add-icon.svg?id=9135b4e0e1c239c36981",

"/images/align-justify-icon.svg": "/images/align-justify-icon.svg?id=ee8d48e636b80417a884",

@@ -36,7 +36,7 @@

:key="rowIndex"

v-if="column.type != 'hidden’"

@click="redirectRow(row.redirect_url)"

v-html="getRowContent(row[column.index])"

v-text="getRowContent(row[column.index])"

:title="column.title ? row[column.index] : '’"

:class="[row.redirect_url ? ‘cursor-pointer’ : '’, column.class || column.index ]"

></td>

@@ -174,7 +174,7 @@

type : "success",

message : response.data.message,

});

EventBus.$emit('refresh_table_data’, {usePrevious: true});

}

}

@@ -189,4 +189,4 @@

}

}

};

</script>

</script>

Related news

GHSA-v829-j9rr-85v9: Cross-site Scripting in krayin/laravel-crm

Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907