Product
The Quasar Framework's server-side rendering (SSR) mechanism in versions prior to 2.22.0 fails to escape HTML characters in meta tags, allowing attackers to inject and execute arbitrary JavaScript in the victim's browser.