Intel

AIKIDO-2024-10283

wireui/wireui is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2024-45803 Published Sep 18, 2024

40

Medium Risk

This Affects:

phpwireui/wireui
1.3.0 - 1.19.2
Fixed in 1.19.3
2.0.0 - 2.1.2
Fixed in 2.1.3
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Cross-site Scripting (XSS) using the Blade template button.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

wireui/wireui is vulnerable to Cross-site Scripting (XSS) in versions 1.3.0 - 1.19.2 and 2.0.0 - 2.1.2.

How to fix this

Upgrade the wireui/wireui library to the patch version.