{"id":"GHSA-254j-mmc5-qhpx","summary":"Smashing Cross-site Scripting vulnerability","details":"Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaScript on the victim's computer. The JavaScript code can then steal data available in the session/cookies depending on the user environment (e.g. if re-using internal URL's for deploying, or cookies that are very permissive) private information may be retrieved by the attacker.","aliases":["CVE-2021-35440"],"modified":"2024-02-16T08:19:53.512122Z","published":"2022-05-24T19:06:56Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-01-27T00:53:50Z","nvd_published_at":"2021-07-06T15:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-35440"},{"type":"WEB","url":"https://github.com/Smashing/smashing/pull/186"},{"type":"WEB","url":"https://github.com/Smashing/smashing/pull/186/commits/f4648137ae77aa2a9ccd14b2e6eeaed2cfb32da3"},{"type":"PACKAGE","url":"https://github.com/Smashing/smashing"},{"type":"WEB","url":"https://github.com/Smashing/smashing/blob/ad7325f159f89854ca4e7d94e7be9bee507b6d46/CHANGELOG.md"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/smashing/CVE-2021-35440.yml"}],"affected":[{"package":{"name":"smashing","ecosystem":"RubyGems","purl":"pkg:gem/smashing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.5"}]}],"versions":["1.0.0","1.1.0","1.2.0","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-254j-mmc5-qhpx/GHSA-254j-mmc5-qhpx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}