Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdtd3AtcGdnYy1oNG1q

Cross-site Scripting in Documize

domain/section/markdown/markdown.go in Documize before 3.5.1 mishandles untrusted Markdown content. This was addressed by adding the bluemonday HTML sanitizer to defend against XSS.

Permalink: https://github.com/advisories/GHSA-wmwp-pggc-h4mj
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdtd3AtcGdnYy1oNG1q
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 3 years ago
Updated: about 1 year ago


CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Identifiers: GHSA-wmwp-pggc-h4mj, CVE-2019-19619
References: Repository: https://github.com/documize/community
Blast Radius: 1.0

Affected Packages

go:github.com/documize/community
Dependent packages: 0
Dependent repositories: 0
Downloads:
Affected Version Ranges: < 3.5.1
Fixed in: 3.5.1
All affected versions: 0.14.1, 0.14.2, 0.15.0, 0.16.1, 0.17.0, 0.20.0, 0.22.0, 0.24.1, 0.26.0, 0.27.0, 0.28.0, 0.29.0, 0.30.0, 0.31.0, 0.32.0, 0.33.0, 0.34.0, 0.34.1, 0.35.0, 0.36.0, 0.37.0, 0.38.0, 0.39.0, 0.40.0, 0.41.0, 0.42.0, 0.43.0, 0.43.1, 0.44.1, 1.45.0, 1.45.1, 1.45.2, 1.45.3, 1.46.0, 1.46.2, 1.47.0, 1.47.2, 1.48.0, 1.48.1, 1.48.2, 1.49.0, 1.49.1, 1.49.2, 1.50.0, 1.50.1, 1.51.0, 1.52.0, 1.52.1, 1.52.2, 1.53.0, 1.53.1, 1.53.2, 1.53.3, 1.53.4, 1.53.5, 1.53.6, 1.54.0, 1.54.1, 1.55.0, 1.56.0, 1.56.1, 1.57.0, 1.57.1, 1.57.2, 1.57.3, 1.58.0, 1.59.0, 1.59.1, 1.59.2, 1.60.0, 1.61.0, 1.62.0, 1.63.0, 1.63.1, 1.64.0, 1.64.1, 1.64.2, 1.64.3, 1.64.4, 1.65.0, 1.65.1, 1.65.2, 1.65.3, 1.65.4, 1.66.0, 1.67.0, 1.68.0, 1.68.1, 1.69.0, 1.69.1, 1.69.2, 1.70.0, 1.71.0, 1.72.0, 1.73.0, 1.73.1, 1.76.0, 1.76.1, 1.76.2, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.4.2, 2.5.0, 2.5.1, 3.0.0, 3.1.0, 3.1.1, 3.1.2, 3.2.0
All unaffected versions: