VYPR

npm package

baremetrics-calendar

pkg:npm/baremetrics-calendar

Vulnerabilities (1)

  • CVE-2021-32859Feb 20, 2023
    affected <= 1.0.14

    The Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender view. Versions 1.0.14 and prior are prone to cross-site scripting (XSS) when handling untrusted `placeholder` entries. An attacker who is able to influence the f