Vulnerability Description
The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vuetifyjs | Vuetify | >= 2.0.1, < 2.6.10 |
Related Weaknesses (CWE)
References
- https://codepen.io/5v3n-08/pen/MWGKEjYExploitThird Party Advisory
- https://github.com/vuetifyjs/vuetify/commit/ade1434927f55a0eccf3d54f900f24c5fa85PatchThird Party Advisory
- https://github.com/vuetifyjs/vuetify/issues/15757Issue TrackingThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBVUETIFYJS-3024407Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3024406Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-VUETIFY-3019858Third Party Advisory
- https://codepen.io/5v3n-08/pen/MWGKEjYExploitThird Party Advisory
- https://github.com/vuetifyjs/vuetify/commit/ade1434927f55a0eccf3d54f900f24c5fa85PatchThird Party Advisory
- https://github.com/vuetifyjs/vuetify/issues/15757Issue TrackingThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBVUETIFYJS-3024407Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3024406Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-VUETIFY-3019858Third Party Advisory
FAQ
What is CVE-2022-25873?
CVE-2022-25873 is a vulnerability with a CVSS score of 4.6 (MEDIUM). The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.
How severe is CVE-2022-25873?
CVE-2022-25873 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25873?
Check the references section above for vendor advisories and patch information. Affected products include: Vuetifyjs Vuetify.