9.20.0
11 years ago
2 months ago
Known vulnerabilities in the com.googlecode.wicket-jquery-ui:wicket-kendo-ui package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
com.googlecode.wicket-jquery-ui:wicket-kendo-ui is jQuery UI & Kendo UI integration in Wicket. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the WYSIWYG editor. It allows an attacker to submit arbitrary JS code to WYSIWYG editor. How to fix Cross-site Scripting (XSS)? Upgrade | [6.0.0,6.28.1)[7.0.0,7.9.2)[8.0.0-M0,8.0.0-M8.1) |