{"id":"GHSA-c53x-wwx2-pg96","aliases":[],"url":"https://o3.security/vulnerability/GHSA-c53x-wwx2-pg96","summary":"Cross-Site Scripting in @berslucas/liljs","details":"Versions of  `@berslucas/liljs` prior to 1.0.2 are vulnerable to Cross-Site Scripting (XSS). The package uses the unsafe `innerHTML` function without sanitizing input, which may allow attackers to execute arbitrary JavaScript on the victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 1.0.2 or later.","published":"2020-09-03T17:03:58Z","modified":"2021-09-28T17:27:43Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@berslucas/liljs","fixedVersion":"1.0.2"}],"fix":{"url":"https://github.com/bersLucas/liljs/pull/7","label":"bersLucas/liljs#7"},"references":[{"type":"WEB","url":"https://github.com/bersLucas/liljs/pull/7"},{"type":"WEB","url":"https://github.com/bersLucas/liljs/commit/779c0dcd8aba434a1c94db7d1d2d990a629f9a6c"},{"type":"PACKAGE","url":"https://github.com/bersLucas/liljs"},{"type":"WEB","url":"https://github.com/bersLucas/liljs/releases/tag/1.0.2"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-BERSLUCASLILJS-450217"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1016"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-28T17:27:43Z"}}