Impact area
Security
Severity
Medium
Affected element
ServiceNow
UI Script
Salesforce
Static Resource
Rule number
SN-JSL-VUE-LESSTHAN-V2517 (for ServiceNow)
SF-JSL-VUE-LESSTHAN-V2517 (for Salesforce)
Impact #
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when spread attributes in the ssr files are unsanitized and can therefore be attack vectors for untrusted user input.
Remediation
Update vue JS library to the latest version.
Time to fix
30 min
References #
This rule is linked to Common Weakness Enumeration CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’).