GHSA-g9ph-r9hc-34r8
GitHub Security Advisory
Erxes vulnerable to Cross-site Scripting
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in all versions. This results in client-side code execution. The victim must follow a malicious link or be redirected there from malicious web site. There are no known patches.
Affected Packages
npm
erxes
Affected versions:
0
(last affected: 1.0.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.