GHSA-mfv8-q39f-mgfg

Suggest an improvement
Source
https://github.com/advisories/GHSA-mfv8-q39f-mgfg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/07/GHSA-mfv8-q39f-mgfg/GHSA-mfv8-q39f-mgfg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mfv8-q39f-mgfg
Aliases
Published
2019-07-16T00:52:26Z
Modified
2024-09-20T22:02:00.089075Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Cross-site Scripting in invenio-communities
Details

Cross-Site Scripting (XSS) vulnerability in Jinja templates

Impact

A Cross-Site Scripting (XSS) vulnerability was discovered in two Jinja templates in the Invenio-Communities module. The vulnerability allows a user to create a new community and include script element tags inside the description and page fields.

Patches

The problem has been patched in v1.0.0a20.

For more information

If you have any questions or comments about this advisory: * Email us at info@inveniosoftware.org

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:46:01Z"
}
References

Affected packages

PyPI / invenio-communities

Package

Name
invenio-communities
View open source insights on deps.dev
Purl
pkg:pypi/invenio-communities

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.0a20

Affected versions

1.*

1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0a10
1.0.0a11
1.0.0a12
1.0.0a13
1.0.0a14
1.0.0a15
1.0.0a16
1.0.0a17
1.0.0a18
1.0.0a19

Database specific

{
    "last_known_affected_version_range": "<= 1.0.0a19"
}