{"id":"GHSA-rcvr-8whx-3m5p","summary":"Layui cross-site scripting (XSS) vulnerability","details":"layui up to v2.74 was discovered to contain a cross-site scripting (XSS) vulnerability via the data-content parameter.","aliases":["CVE-2023-50550"],"modified":"2024-01-08T15:55:06Z","published":"2023-12-30T18:30:35Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-03T21:42:34Z","nvd_published_at":"2023-12-30T16:15:44Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50550"},{"type":"WEB","url":"https://gitee.com/layui/layui/issues/I8M1C2"},{"type":"WEB","url":"https://gitee.com/layui/layui/issues?utf8=%E2%9C%93&state=all&issue_search=xss"},{"type":"PACKAGE","url":"https://github.com/layui/layui"}],"affected":[{"package":{"name":"layui","ecosystem":"npm","purl":"pkg:npm/layui"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.7.5"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.7.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-rcvr-8whx-3m5p/GHSA-rcvr-8whx-3m5p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}