{"id":"GHSA-q8wc-9xvp-g3c3","summary":"Cross-site scripting in Sakai","details":"Sakai through 12.6 allows XSS via a chat user name.","aliases":["CVE-2019-16148"],"modified":"2023-11-01T04:50:35.242925Z","published":"2019-09-23T18:33:18Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2019-09-19T14:57:19Z","nvd_published_at":"2019-09-09T13:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16148"},{"type":"WEB","url":"https://github.com/sakaiproject/sakai/pull/6971"}],"affected":[{"package":{"name":"org.sakaiproject:chat-base","ecosystem":"Maven","purl":"pkg:maven/org.sakaiproject/chat-base"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"12.6"}]}],"versions":["10.1","10.2","10.3","10.4","10.6","10.7","11.0","11.1","11.2","11.3","11.4","12.0","12.1","12.2","12.3","12.4","12.5","12.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/09/GHSA-q8wc-9xvp-g3c3/GHSA-q8wc-9xvp-g3c3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}