github.com/victoriametrics/victorialogs-datasource is vulnerable to Cross-Site Scripting (XSS)
41
Medium Risk
Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) attacks due to unsanitized href attributes. This vulnerability arises when user-controlled input is assigned directly to the href property of anchor tags without proper sanitization. An attacker can exploit this by injecting malicious JavaScript URLs (for example, javascript:alert('XSS')) into the href field. If unsuspecting users click on the manipulated link, the arbitrary script executes in their browser context, potentially leading to session hijacking or other malicious actions.
You are affected if you are using a version that falls within the vulnerable range.
github.com/victoriametrics/victorialogs-datasource is vulnerable to Cross-Site Scripting (XSS) in versions 0.15.0 - 0.21.2.
Upgrade the github.com/victoriametrics/victorialogs-datasource library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant