{"id":"GHSA-mpjf-8cmf-p789","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mpjf-8cmf-p789","summary":"Cross-Site Scripting in jingo","details":"Versions of `jingo` prior to 1.9.2 are vulnerable to Cross-Site Scripting (XSS). If malicious input such as `<script>alert(1)</script>` is placed in the content of a wiki page, Jingo does not properly encode the input and it is executed instead of rendered as text.\n\n\n## Recommendation\n\nUpgrade to version 1.9.2","published":"2020-09-01T21:25:46Z","modified":"2020-08-31T18:34:28Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"jingo","fixedVersion":"1.9.2"}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/750"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:34:28Z"}}