{ "schema_version": "1.4.0", "id": "GHSA-7q42-98q6-h3r9", "modified": "2022-05-24T17:06:02Z", "published": "2022-05-24T17:06:02Z", "aliases": [ "CVE-2019-20375" ], "details": "A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via the value parameter in a localization (loc) command to elogd.c.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-20375" }, { "type": "WEB", "url": "https://bitbucket.org/ritt/elog/commits/eefdabb714f26192f585083ef96c8413e459a1d1" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-01-10T05:15:00Z" } }