GHSA-h847-63fg-vm6c

Suggest an improvement
Source
https://github.com/advisories/GHSA-h847-63fg-vm6c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h847-63fg-vm6c/GHSA-h847-63fg-vm6c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h847-63fg-vm6c
Aliases
Published
2022-05-14T03:11:44Z
Modified
2024-04-23T23:26:47.432652Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
nZEDb Cross-site Scripting (XSS) in the 404 error page
Details

nZEDb before 0.8.0.0 has XSS in the 404 error page.

Database specific
{
    "nvd_published_at": "2018-06-05T06:29:00Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-23T22:53:39Z"
}
References

Affected packages

Packagist / nzedb/nzedb

Package

Name
nzedb/nzedb
Purl
pkg:composer/nzedb/nzedb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.0.0

Affected versions

v0.*

v0.6.0-RC1
v0.6.0-RC2
v0.6.0-RC3
v0.6.0-RC4
v0.6.0-RC5
v0.6.0-RC6
v0.6.0
v0.6.0.1
v0.6.0.2
v0.6.1-RC1
v0.6.1
v0.6.1.1
v0.6.1.2
v0.6.1.3
v0.6.2-RC1
v0.6.2-RC2
v0.6.2
v0.6.2.1
v0.6.2.2
v0.6.2.3
v0.6.2.4
v0.6.3-RC1
v0.6.3
v0.6.3.1
v0.6.3.2-RC1
v0.6.3.2
v0.6.3.3-RC1
v0.6.3.3
v0.6.4.0-RC1
v0.6.4.0
v0.6.4.1-RC1
v0.6.4.1
v0.6.5.0-RC1
v0.6.5.0
v0.6.5.1
v0.6.5.2-RC1
v0.6.5.2
v0.6.5.3
v0.6.6.0
v0.6.6.1
v0.6.6.2
v0.6.7.0
v0.6.8.0
v0.6.8.1
v0.6.9.0
v0.7.0.0
v0.7.1.0
v0.7.1.1
v0.7.1.2
v0.7.2.0
v0.7.2.1
v0.7.3.0
v0.7.3.1
v0.7.3.2
v0.7.3.3
v0.7.4.0
v0.7.4.1