{ "schema_version": "1.4.0", "id": "GHSA-m8fw-534v-xm85", "modified": "2020-08-31T18:31:00Z", "published": "2019-06-04T15:43:29Z", "aliases": [], "summary": "Cross-Site Scripting (XSS) in cloudcmd", "details": "Versions of `cloudcmd` before 9.1.6 are vulnerable to cross-site scripting (XSS) when listing files in a directory. The attacker must control the name of a file for this vulnerability to be exploitable.\n\n\n## Recommendation\n\nUpdate to version 9.1.6 or later.", "severity": [], "affected": [ { "package": { "ecosystem": "npm", "name": "cloudcmd" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "9.1.6" } ] } ] } ], "references": [ { "type": "WEB", "url": "https://github.com/coderaiser/cloudcmd/commit/23f4d4702cd3d473977285f26ea2ae7206b45f38" }, { "type": "WEB", "url": "https://hackerone.com/reports/341044" }, { "type": "WEB", "url": "https://hackerone.com/reports/341044)" }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/642" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2019-06-04T15:43:12Z", "nvd_published_at": null } }