The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| vuetify(npm) | 2.0.0-beta.4 | 2.6.10 | N/A |
| org.webjars.npm:vuetify(Maven) | 2.0.0-beta.4 | 2.6.10 | N/A |
CVSS Metrics