XSS vulnerability in translations
Moderate severity
GitHub Reviewed
Published
Jan 12, 2022
to the GitHub Advisory Database
•
Updated Jan 11, 2023
Package
Affected versions
>= 3.1.0, < 3.1.29
>= 4.1.0, < 4.1.17
>= 4.2.0, < 4.2.8
Patched versions
3.1.29
4.1.17
4.2.8
Description
Reviewed
Jan 10, 2022
Published to the GitHub Advisory Database
Jan 12, 2022
Last updated
Jan 11, 2023
Summary
An attacker with admin privileges and access to Translations management functionality may add JS payload to translation values via:
Workarounds
There are no workarounds that address this vulnerability.
References