Cross site scripting in Metro UI
Moderate severity
GitHub Reviewed
Published
Oct 11, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Oct 11, 2022
Published to the GitHub Advisory Database
Oct 11, 2022
Reviewed
Oct 12, 2022
Last updated
Feb 3, 2023
Metro UI v4.4.0 to v4.5.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function. User input is not properly sanitized before rendering in the
textarea
component.References