panel is vulnerable to Cross-site Scripting (XSS)
40
Medium Risk
Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) in authentication handling. The vulnerability occurs when the login endpoint fails to properly sanitize parameters during authentication, allowing URL-encoded scripts to execute instead of returning expected errors. An attacker can exploit this by crafting a malicious URL and tricking victims into clicking it, enabling arbitrary JavaScript execution in their browser session to steal credentials or hijack authentication tokens.
You are affected if you are using a version that falls within the vulnerable range.
panel is vulnerable to Cross-site Scripting (XSS) in versions 0.14.0 - 1.7.3.
Upgrade the panel library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant