{"id":"GO-2021-0086","summary":"Cross-site scripting in github.com/documize/community","details":"HTML content in markdown is not sanitized during rendering, possibly allowing XSS if used to render untrusted user input.","aliases":["CVE-2019-19619","GHSA-wmwp-pggc-h4mj"],"modified":"2024-05-20T16:03:47Z","published":"2021-04-14T20:04:52Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2021-0086"},"references":[{"type":"FIX","url":"https://github.com/documize/community/commit/a4384210d4d0d6b18e6fdb7e155de96d4a1cf9f3"}],"affected":[{"package":{"name":"github.com/documize/community","ecosystem":"Go","purl":"pkg:golang/github.com/documize/community"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.76.3-0.20191119114751-a4384210d4d0"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/documize/community/domain/section/markdown","symbols":["Provider.Render"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2021-0086.json"}}],"schema_version":"1.7.3"}