Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1oM3ZxLXd2OGotMzZnd80hOQ
Cross-site Scripting in Scratch-Svg-Renderer
A DOM-based cross-site scripting (XSS) vulnerability in Scratch-Svg-Renderer v0.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted sb3 file.
Permalink: https://github.com/advisories/GHSA-h3vq-wv8j-36gwJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oM3ZxLXd2OGotMzZnd80hOQ
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 2 years ago
Updated: about 1 year ago
Identifiers: GHSA-h3vq-wv8j-36gw, CVE-2020-27428
References:
- https://nvd.nist.gov/vuln/detail/CVE-2020-27428
- https://github.com/LLK/scratch-svg-renderer/commit/7c74ec7de3254143ec3c557677f5355a90a3d07f
- https://github.com/advisories/GHSA-h3vq-wv8j-36gw
Blast Radius: 0.0
Affected Packages
npm:scratch-svg-renderer
Dependent packages: 98Dependent repositories: 264
Downloads: 11,839 last month
Affected Version Ranges: <= 0.2.0
No known fixed version
All affected versions: 0.1.0, 0.2.0