GHSA-vr95-p7q6-8m9q

Source
https://github.com/advisories/GHSA-vr95-p7q6-8m9q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-vr95-p7q6-8m9q/GHSA-vr95-p7q6-8m9q.json
Published
2024-05-15T22:16:06Z
Modified
2024-05-15T22:31:34.412107Z
Summary
Laravel Cross-site Scripting (XSS) vulnerability in blade templating
Details

Laravel 7.1.2 addresses a possible XSS related attack vector in the Laravel 7.x Blade Component tag attributes when users are allowed to dictate the value of attributes. All Laravel 7.x users are encouraged to upgrade as soon as possible.

References

Affected packages

Packagist / laravel/framework

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.1.2

Affected versions

v7.*

v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.0.8
v7.1.0
v7.1.1