GHSA-7cv6-gvx3-m54m
Dashboard / Vulnerabilities / GHSA-7cv6-gvx3-m54m
Summary: Cross-Site Scripting in keystone
Details: Versions of `keystone` prior to 4.0.0 are vulnerable to Cross-Site Scripting (XSS). The package fails to properly encode rendered HTML on admin-created blog posts. This allows attackers to execute arbitrary JavaScript in the victim's browser. Exploiting this vulnerability requires having access to an admin account. ## Recommendation Update to version 4.0.0 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-15881, https://github.com/keystonejs/keystone/issues/4437, https://github.com/keystonejs/keystone/pull/4478, https://github.com/advisories/GHSA-7cv6-gvx3-m54m, https://securelayer7.net/download/pdf/KeystoneJS-Pentest-Report-SecureLayer7.pdf, https://www.npmjs.com/advisories/981, http://blog.securelayer7.net/keystonejs-open-source-penetration-testing-report, http://www.securityfocus.com/bid/101541
Affected packages
Package
Name: keystone
Purl: pkg:npm/keystone
Affected ranges
Type: SEMVER
Events:
