{ "schema_version": "1.4.0", "id": "GHSA-jj8r-p9f5-fmvv", "modified": "2021-08-30T17:07:59Z", "published": "2021-08-30T17:22:25Z", "aliases": [ "CVE-2021-36785" ], "summary": "Cross-site Scripting in TYPO3 extension", "details": "The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N" } ], "affected": [ { "package": { "ecosystem": "Packagist", "name": "miniorange/miniorange-saml" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "1.4.3" } ] } ] } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36785" }, { "type": "WEB", "url": "https://github.com/miniOrangeDev/miniorange-saml-typo3-sso/commit/1fe2802267ffe1b48823d9d8b3a496c870a0af48" }, { "type": "PACKAGE", "url": "https://github.com/miniOrangeDev/miniorange-saml-typo3-sso" }, { "type": "WEB", "url": "https://typo3.org/help/security-advisories/security" }, { "type": "WEB", "url": "https://typo3.org/security/advisory/typo3-ext-sa-2021-011" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-08-30T17:07:59Z", "nvd_published_at": "2021-08-13T17:15:00Z" } }