{"id":"GHSA-qqv6-5w6p-3pgr","summary":"Moderate severity vulnerability that affects org.hswebframework.web:hsweb-commons","details":"An issue was discovered in hsweb 3.0.4. It is a reflected XSS vulnerability due to the absence of type parameter checking in FlowableModelManagerController.java.","aliases":["CVE-2018-20594"],"modified":"2023-11-01T04:49:21.423126Z","published":"2019-01-04T17:43:30Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:52:34Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-20594"},{"type":"WEB","url":"https://github.com/hs-web/hsweb-framework/issues/107"},{"type":"WEB","url":"https://github.com/hs-web/hsweb-framework/commit/b72a2275ed21240296c6539bae1049c56abb542f"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qqv6-5w6p-3pgr"},{"type":"PACKAGE","url":"https://github.com/hs-web/hsweb-framework"}],"affected":[{"package":{"name":"org.hswebframework.web:hsweb-commons","ecosystem":"Maven","purl":"pkg:maven/org.hswebframework.web/hsweb-commons"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.0.4"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3","3.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-qqv6-5w6p-3pgr/GHSA-qqv6-5w6p-3pgr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}