{"id":"GHSA-hgr5-82rc-p936","aliases":[],"url":"https://o3.security/vulnerability/GHSA-hgr5-82rc-p936","summary":"Cross-Site Scripting in md-data-table","details":"All versions of `md-data-table` are vulnerable to cross-site scripting (XSS). This vulnerability is exploitable if an attacker has control over data that is rendered by `mdt-row`\n\n\n## Recommendation\n\nAs there is no fix for this vulnerability at this time we recommend either selecting another package to perform this functionality or properly sanitizing all user data prior to rendering with `md-data-table`","published":"2020-09-01T21:24:41Z","modified":"2020-08-31T18:34:23Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"md-data-table","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/748"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:34:23Z"}}