{"id":"GHSA-j7wp-vjj6-cp5m","summary":"Cross-Site Scripting in @progress/kendo-angular-editor","details":"Kendo UI for Angular Editor Component (npm package @progress/kendo-angular-editor) before version 1.2.3 is vulnerable to Cross-Site Scripting. When the Editor content contains potentially malicious scripts in element event handlers, they get executed.\nAdding the following content to the Editor value demonstrates the issue: `\u003cimg src=\"\" onerror=alert(document.domain)\u003e`.","modified":"2021-09-23T18:55:46Z","published":"2020-08-11T19:40:10Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-08-11T19:39:52Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"HIGH"},"references":[{"type":"PACKAGE","url":"https://github.com/telerik/kendo-angular-editor"},{"type":"WEB","url":"https://stackblitz.com/edit/angular-6xzuzp-tef7lb?file=app/app.component.ts"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1549"}],"affected":[{"package":{"name":"@progress/kendo-angular-editor","ecosystem":"npm","purl":"pkg:npm/%40progress/kendo-angular-editor"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-j7wp-vjj6-cp5m/GHSA-j7wp-vjj6-cp5m.json"}}],"schema_version":"1.9.0"}