{ "schema_version": "1.4.0", "id": "GHSA-49r3-3h96-rwj6", "modified": "2020-08-31T18:41:54Z", "published": "2019-06-13T19:09:31Z", "aliases": [], "summary": "Cross-Site Scripting in ids-enterprise", "details": "Versions of `ids-enterprise` prior to 4.18.2 are vulnerable to Cross-Site Scripting (XSS). The `soho-dropdown` component does not properly encode its output and may allow attackers to execute arbitrary JavaScript.\n\n\n## Recommendation\n\nUpgrade to version 4.18.2 or later", "severity": [], "affected": [ { "package": { "ecosystem": "npm", "name": "ids-enterprise" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "4.18.2" } ] } ] } ], "references": [ { "type": "WEB", "url": "https://github.com/infor-design/enterprise-ng/issues/503" }, { "type": "WEB", "url": "https://github.com/infor-design/enterprise/commit/6bd74d8f38c268b22f31e8169316e065e0093362" }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/956" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2019-06-13T19:09:01Z", "nvd_published_at": null } }