Description
The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6907 | The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component. |
Github GHSA |
GHSA-q4q5-c5cv-2p68 | Vuetify Cross-site Scripting vulnerability |
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-17T03:28:38.073Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25873
No data.
Status : Modified
Published: 2022-09-18T15:15:09.660
Modified: 2024-11-21T06:53:08.890
Link: CVE-2022-25873
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA