{"id":"GHSA-5chx-gg25-v37m","summary":"Cross-site Scripting in xain","details":"XSS is possible via the use of the order query parameter. An example request\n  would look like:\n  ```\n  http://host/ressources?order=%27\u003e\u003cscript\u003ealert(1);\u003c/script\u003e\n  ```","aliases":["CVE-2018-20302"],"modified":"2025-12-10T00:42:25.426255Z","published":"2022-04-12T21:17:38Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-04-12T21:17:38Z","nvd_published_at":null,"cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-20302"},{"type":"WEB","url":"https://github.com/smpallen99/xain/issues/18"},{"type":"WEB","url":"https://github.com/dependabot/elixir-security-advisories/blob/master/packages/xain/2018-09-03.yml"},{"type":"PACKAGE","url":"https://github.com/smpallen99/xain"}],"affected":[{"package":{"name":"xain","ecosystem":"Hex","purl":"pkg:hex/xain"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.2"}]}],"versions":["0.5.2","0.5.3","0.6.0","0.6.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-5chx-gg25-v37m/GHSA-5chx-gg25-v37m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}