{"id":"GHSA-q4q5-c5cv-2p68","summary":"Vuetify Cross-site Scripting vulnerability","details":"The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.","aliases":["CVE-2022-25873"],"modified":"2023-11-08T04:08:50.276348Z","published":"2022-09-19T00:00:28Z","database_specific":{"github_reviewed_at":"2022-09-21T20:58:44Z","nvd_published_at":"2022-09-18T15:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25873"},{"type":"WEB","url":"https://github.com/vuetifyjs/vuetify/issues/15757"},{"type":"WEB","url":"https://github.com/vuetifyjs/vuetify/commit/ade1434927f55a0eccf3d54f900f24c5fa85a176"},{"type":"WEB","url":"https://codepen.io/5v3n-08/pen/MWGKEjY"},{"type":"PACKAGE","url":"https://github.com/vuetifyjs/vuetify"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBVUETIFYJS-3024407"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3024406"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-VUETIFY-3019858"}],"affected":[{"package":{"name":"vuetify","ecosystem":"npm","purl":"pkg:npm/vuetify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0-beta.4"},{"fixed":"2.6.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-q4q5-c5cv-2p68/GHSA-q4q5-c5cv-2p68.json"}},{"package":{"name":"org.webjars.npm:vuetify","ecosystem":"Maven","purl":"pkg:maven/org.webjars.npm/vuetify"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0-beta.4"},{"fixed":"2.6.10"}]}],"versions":["2.0.0","2.0.0-beta.4","2.0.0-beta.5","2.0.0-beta.6","2.0.0-beta.7","2.0.0-beta.8","2.0.0-beta.9","2.0.1","2.0.10","2.0.11","2.0.14","2.0.15","2.0.16","2.0.18","2.0.2","2.0.3","2.0.4","2.0.5","2.0.7","2.0.9","2.1.0","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.14","2.1.15","2.1.16","2.1.18","2.1.4","2.1.5","2.1.6","2.1.7","2.1.9","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.14","2.2.15","2.2.16","2.2.17","2.2.18","2.2.19","2.2.20","2.2.21","2.2.22","2.2.23","2.2.25","2.2.28","2.2.29","2.2.3","2.2.30","2.2.31","2.2.32","2.2.33","2.2.34","2.2.4","2.2.5","2.2.6","2.2.8","2.2.9","2.3.0","2.3.1","2.3.10","2.3.12","2.3.13","2.3.14","2.3.15","2.3.16","2.3.17","2.3.18","2.3.19","2.3.2","2.3.20","2.3.21","2.3.22","2.3.23","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.3.8","2.3.9","2.4.0","2.4.0-beta.0","2.4.1","2.4.10","2.4.11","2.4.2","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","2.4.9","2.5.0","2.5.1","2.5.10","2.5.13","2.5.14","2.5.2","2.5.3","2.5.4","2.5.5","2.5.6","2.5.7","2.5.8","2.5.9","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.6.6","2.6.7","2.6.8","2.6.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-q4q5-c5cv-2p68/GHSA-q4q5-c5cv-2p68.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}