{ "schema_version": "1.4.0", "id": "GHSA-v5x4-jpcc-h4rv", "modified": "2022-05-24T17:33:58Z", "published": "2022-05-24T17:33:58Z", "aliases": [ "CVE-2020-26221" ], "details": "touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which could result in hijacking of the user's cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser action. The issue is patched in version 2.0.", "severity": [], "affected": [], "references": [ { "type": "WEB", "url": "https://github.com/puncsky/touchbase.ai/security/advisories/GHSA-jc3v-h36h-6mx3" }, { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26221" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-11-11T23:15:00Z" } }