select2 XSS issue with current version
-
In Select2 through version 4.0.8, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data. For more info see https://security.snyk.io/vuln/SNYK-JS-SELECT2-456562
Please consider patching this asap to the latest version 4.0.13
Viewing 5 replies - 1 through 5 (of 5 total)
Viewing 5 replies - 1 through 5 (of 5 total)
- You must be logged in to reply to this topic.