diff --git a/advisories/unreviewed/2022/05/GHSA-378w-3fqw-3555/GHSA-378w-3fqw-3555.json b/advisories/unreviewed/2022/05/GHSA-378w-3fqw-3555/GHSA-378w-3fqw-3555.json index 076eddbf8b35f..936109d6b8205 100644 --- a/advisories/unreviewed/2022/05/GHSA-378w-3fqw-3555/GHSA-378w-3fqw-3555.json +++ b/advisories/unreviewed/2022/05/GHSA-378w-3fqw-3555/GHSA-378w-3fqw-3555.json @@ -1,12 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-378w-3fqw-3555", - "modified": "2022-05-14T01:37:58Z", + "modified": "2023-02-02T05:04:12Z", "published": "2022-05-14T01:37:58Z", "aliases": [ "CVE-2018-19782" ], - "details": "Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.", + "summary": "Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS <1.13.0", + "details": "Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS <1.13.0 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.", "severity": [ { "type": "CVSS_V3", @@ -14,13 +15,35 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.13.0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-19782" }, + { + "type": "PACKAGE", + "url": "https://github.com/FreshRSS/FreshRSS" + }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/45954"