Headline
GHSA-633r-r4p8-pw3w: Cross site scripting in Metro UI
Metro UI v4.4.0 to v4.5.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function. User input is not properly sanitized before rendering in the textarea
component.
Cross site scripting in Metro UI
Moderate severity GitHub Reviewed Published Oct 11, 2022 • Updated Oct 12, 2022
Related news
CVE-2022-41376: Metro UI v4.4.0 Components Library Reflected XSS Injection
Metro UI v4.4.0 to v4.5.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function.