{"id":"CVE-2019-13970","details":"In antSword before 2.1.0, self-XSS in the database configuration leads to code execution via modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index.js, or modules/database/php/index.js.","aliases":["GHSA-hq75-ggc3-8h3q"],"modified":"2026-08-07T14:52:40.065402Z","published":"2019-07-19T06:15:10.927Z","references":[{"type":"ADVISORY","url":"https://github.com/AntSwordProject/antSword/compare/ed01dea...834063a"},{"type":"FIX","url":"https://github.com/AntSwordProject/antSword/commit/4b932e81447b4b0475f4fce45525547395c249d3"},{"type":"EVIDENCE","url":"https://github.com/AntSwordProject/antSword/issues/151"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/antswordproject/antsword","events":[{"introduced":"0"},{"fixed":"834063ac07f5b6295bff9ca3e45db8760367cab0"},{"fixed":"4b932e81447b4b0475f4fce45525547395c249d3"}],"database_specific":{"cpe":"cpe:2.3:a:antsword_project:antsword:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.1.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.0.7.2","2.0.7.1","2.0.7","2.0.6","2.0.5","2.0.4","2.0.3","2.0.2","2.0.1","2.0.0","1.2.1","1.1.2","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13970.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}