templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
{ "cpe": "cpe:2.3:a:etherpad:etherpad:1.7.5:*:*:*:*:*:*:*", "source": [ "CPE_STRING", "REFERENCES" ], "extracted_events": [ { "introduced": "1.7.5" }, { "last_affected": "1.7.5" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-18209.json"