{"id":"CVE-2020-28470","aliases":[],"url":"https://o3.security/vulnerability/CVE-2020-28470","summary":"Cross-site Scripting (XSS) in @scullyio/scully","details":"This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.","published":"2021-04-13T15:28:01Z","modified":"2026-03-13T21:57:08.672477Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@scullyio/scully","fixedVersion":"1.0.9"},{"ecosystem":"npm","name":"@scullyio/ng-lib","fixedVersion":"1.0.1"}],"fix":{"url":"https://github.com/scullyio/scully/pull/1182","label":"scullyio/scully#1182"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28470"},{"type":"WEB","url":"https://github.com/scullyio/scully/pull/1182"},{"type":"PACKAGE","url":"https://github.com/scullyio/scully"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-SCULLYIOSCULLY-1055829"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-13T21:57:08.672477Z"}}