Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-633r-r4p8-pw3w: Cross site scripting in Metro UI

Metro UI v4.4.0 to v4.5.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function. User input is not properly sanitized before rendering in the textarea component.

ghsa
#xss#vulnerability#git#java#perl

Cross site scripting in Metro UI

Moderate severity GitHub Reviewed Published Oct 11, 2022 • Updated Oct 12, 2022

Related news

CVE-2022-41376: Metro UI v4.4.0 Components Library Reflected XSS Injection

Metro UI v4.4.0 to v4.5.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function.