{"id":"GHSA-r3xc-47qg-h929","aliases":[],"url":"https://o3.security/vulnerability/GHSA-r3xc-47qg-h929","summary":"Cross-Site Scripting in @ionic/core","details":"Versions of  `@ionic/core` prior to 4.0.3, 4.1.3, 4.2.1 or 4.3.1 are vulnerable to Cross-Site Scripting (XSS). The package uses the unsafe `innerHTML` function without sanitizing input, which may allow attackers to execute arbitrary JavaScript on the victim's browser. This issue affects the components:\n- `<ion-alert>.message`\n- `<ion-searchbar>.placeholder`\n- `<ion-infinite-scroll-content>.loadingText`\n- `<ion-refresher-content>.pullingText`\n- `<ion-refresher-content>.refershingText`\n\n\n## Recommendation\n\n- If you are using @ionic/core 4.0.x, upgrade to 4.0.3 or later.\n- If you are using @ionic/core 4.1.x, upgrade to 4.1.3 or later.\n- If you are using @ionic/core 4.2.x, upgrade to 4.2.1 or later.\n- If you are using @ionic/core 4.3.x, upgrade to 4.3.1 or later.","published":"2020-09-03T17:06:09Z","modified":"2021-09-28T17:38:45Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@ionic/core","fixedVersion":"4.0.3"},{"ecosystem":"npm","name":"@ionic/core","fixedVersion":"4.1.3"},{"ecosystem":"npm","name":"@ionic/core","fixedVersion":"4.2.1"},{"ecosystem":"npm","name":"@ionic/core","fixedVersion":"4.3.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ionic-team/ionic/issues/18065"},{"type":"PACKAGE","url":"https://github.com/ionic-team/ionic"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1023"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-28T17:38:45Z"}}