Toast UI Grid is a component to display and edit data. Versions prior to 4.21.3 are vulnerable to cross-site scripting attacks when pasting specially crafted content into editable cells. This issue was fixed in version 4.21.3. There are no known workarounds.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://securitylab.github.com/advisories/GHSL-2022-029_nhn_tui_grid/ | third party advisory exploit |
https://github.com/nhn/tui.grid/commit/e9db5968675ae113c07efc091cce210f2b26854f | third party advisory patch |