{"id":"GHSA-whv6-rj84-2vh2","aliases":[],"url":"https://o3.security/vulnerability/GHSA-whv6-rj84-2vh2","summary":"Cross-Site Scripting in nextcloud-vue-collections","details":"Versions of `nextcloud-vue-collections` prior to 0.4.2 are vulnerable to Cross-Site Scripting (XSS).  The `v-tooltip` component has an insecure `defaultHTML` configuration that allows arbitrary JavaScript to be injected in the tooltip of a collection item. This allows attackers to execute arbitrary code in a victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 0.4.2 or later.","published":"2020-09-04T17:21:58Z","modified":"2021-10-04T20:36:41Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"nextcloud-vue-collections","fixedVersion":"0.4.2"}],"fix":{"url":"https://github.com/juliushaertl/nextcloud-vue-collections/commit/8ec1fca214f003538cec4137792ede928f25f583","label":"juliushaertl/nextcloud-vue-collections@8ec1fca"},"references":[{"type":"WEB","url":"https://github.com/juliushaertl/nextcloud-vue-collections/commit/8ec1fca214f003538cec4137792ede928f25f583"},{"type":"PACKAGE","url":"https://github.com/juliushaertl/nextcloud-vue-collections"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1442"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-10-04T20:36:41Z"}}