{ "schema_version": "1.4.0", "id": "GHSA-crfx-5phg-hmw9", "modified": "2020-08-31T18:41:52Z", "published": "2019-06-13T18:59:12Z", "aliases": [], "summary": "Cross-Site Scripting in ids-enterprise", "details": "Versions of `ids-enterprise` prior to 4.18.2 are vulnerable to Cross-Site Scripting (XSS). Script tags in the `soho-autocomplete` component are not properly encoded and may allow attackers to execute arbitrary JavaScript.\n\n\n## Recommendation\n\nUpgrade to version 4.18.2 or later", "severity": [], "affected": [ { "package": { "ecosystem": "npm", "name": "ids-enterprise" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "4.18.2" } ] } ] } ], "references": [ { "type": "WEB", "url": "https://github.com/infor-design/enterprise-ng/issues/502" }, { "type": "WEB", "url": "https://github.com/infor-design/enterprise/commit/ce7b335bb614a6720867abf5b8eb351deb13aed1" }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/955" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2019-06-13T18:47:35Z", "nvd_published_at": null } }