{"id":"CVE-2016-1000235","aliases":[],"url":"https://o3.security/vulnerability/CVE-2016-1000235","summary":"fuelux vulnerable to Cross-Site Scripting in Pillbox feature","details":"Affected versions of `fuelux` contain a cross-site scripting vulnerability in the Pillbox feature. By supplying a script as a value for a new pillbox, it is possible to cause arbitrary script execution.\n\n## Recommendation\n\nUpdate to version 3.15.7 or later.","published":"2020-09-01T15:55:56Z","modified":"2023-11-08T03:58:08.090761Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"fuelux","fixedVersion":"3.15.7"}],"fix":{"url":"https://github.com/ExactTarget/fuelux/pull/1856","label":"ExactTarget/fuelux#1856"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000235"},{"type":"WEB","url":"https://github.com/ExactTarget/fuelux/issues/1841"},{"type":"WEB","url":"https://github.com/ExactTarget/fuelux/pull/1856"},{"type":"PACKAGE","url":"https://github.com/ExactTarget/fuelux"},{"type":"WEB","url":"https://www.npmjs.com/advisories/133"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:58:08.090761Z"}}