{"id":"GHSA-cfxh-frx4-9gjg","aliases":[],"url":"https://o3.security/vulnerability/GHSA-cfxh-frx4-9gjg","summary":"Cross-site Scripting in @spscommerce/ds-react","details":"### Impact\nXSS, anyone using the SPS Select with options prop populated from user input is impacted. If these options are stored, then it could have been a stored XSS. \n\n### Patches\nThe code has been patched for version 7 of woodland. Users should upgrade to 7.17.4 or higher\n\n### Workarounds\nThis is not recommended. If you are not upgrading then you would need to sanitize your options yourself (including those currently stored in databases). This is not recommended.\n\n### References\nhttps://github.com/SPSCommerce/woodland/blob/c49e999f97f3c0b56502859f4de1e8c6666dd74d/packages/ds-react/src/option-list/SpsOptionList.tsx#L559\n","published":"2023-12-15T03:13:18Z","modified":"2023-12-15T03:13:18Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@spscommerce/ds-react","fixedVersion":"7.17.4"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/SPSCommerce/woodland/security/advisories/GHSA-cfxh-frx4-9gjg"},{"type":"PACKAGE","url":"https://github.com/SPSCommerce/woodland"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-12-15T03:13:18Z"}}