{"id":"GHSA-77cq-wgpf-g449","summary":"Coaster CMS Stored Cross-site Scripting vulnerability","details":"A Stored Cross-site Scripting vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product.","aliases":["CVE-2018-17876"],"modified":"2024-04-23T23:12:01.277949Z","published":"2022-05-14T01:58:19Z","database_specific":{"nvd_published_at":"2018-10-04T19:29:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-04-23T22:57:39Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-17876"},{"type":"PACKAGE","url":"https://github.com/CoasterCms/coastercms"},{"type":"WEB","url":"http://packetstormsecurity.com/files/149647/Coaster-CMS-5.5.0-Cross-Site-Scripting.html"}],"affected":[{"package":{"name":"web-feet/coastercms","ecosystem":"Packagist","purl":"pkg:composer/web-feet/coastercms"},"versions":["5.5.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-77cq-wgpf-g449/GHSA-77cq-wgpf-g449.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}