{"id":"GHSA-whv6-rj84-2vh2","summary":"Cross-Site Scripting in nextcloud-vue-collections","details":"Versions of `nextcloud-vue-collections` prior to 0.4.2 are vulnerable to Cross-Site Scripting (XSS).  The `v-tooltip` component has an insecure `defaultHTML` configuration that allows arbitrary JavaScript to be injected in the tooltip of a collection item. This allows attackers to execute arbitrary code in a victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 0.4.2 or later.","modified":"2021-10-04T20:36:41Z","published":"2020-09-04T17:21:58Z","database_specific":{"github_reviewed_at":"2020-08-31T18:59:28Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/juliushaertl/nextcloud-vue-collections/commit/8ec1fca214f003538cec4137792ede928f25f583"},{"type":"PACKAGE","url":"https://github.com/juliushaertl/nextcloud-vue-collections"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1442"}],"affected":[{"package":{"name":"nextcloud-vue-collections","ecosystem":"npm","purl":"pkg:npm/nextcloud-vue-collections"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-whv6-rj84-2vh2/GHSA-whv6-rj84-2vh2.json"}}],"schema_version":"1.9.0"}