{"id":"CVE-2016-1000228","aliases":[],"url":"https://o3.security/vulnerability/CVE-2016-1000228","summary":"DOM-based XSS in gmail-js","details":"Affected versions of `gmail-js` are vulnerable to cross-site scripting in the `tools.parse_response`, `helper.get.visible_emails_post`, and `helper.get.email_data_post` functions, which pass user input directly into the Function constructor.\n\n\n\n## Recommendation\n\nUpdate to version 0.6.5 or later.","published":"2020-09-01T15:32:04Z","modified":"2023-11-08T03:58:07.661328Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"gmail-js","fixedVersion":"0.6.5"}],"fix":{"url":"https://github.com/KartikTalwar/gmail.js/commit/a83436f499f9c01b04280af945a5a81137b6baf1","label":"KartikTalwar/gmail.js@a83436f"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000228"},{"type":"WEB","url":"https://github.com/KartikTalwar/gmail.js/issues/281"},{"type":"WEB","url":"https://github.com/KartikTalwar/gmail.js/commit/a83436f499f9c01b04280af945a5a81137b6baf1"},{"type":"PACKAGE","url":"https://github.com/KartikTalwar/gmail.js"},{"type":"WEB","url":"https://www.npmjs.com/advisories/125"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:58:07.661328Z"}}