id: PYSEC-2021-347 details: Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of the component 'simiki/blob/master/simiki/generators.py'. affected: - package: name: simiki ecosystem: PyPI purl: pkg:pypi/simiki ranges: - type: ECOSYSTEM events: - introduced: '0' versions: - 0.1.0 - 0.2.0 - 0.2.1 - 0.2.2 - 0.3.0 - 0.3.1 - 0.4.0 - 0.4.1 - 0.5.0 - 1.0.0 - 1.0.1 - 1.0.2 - 1.0.3 - '1.1' - '1.2' - 1.2.1 - 1.2.2 - 1.2.3 - 1.2.4 - '1.3' - '1.4' - 1.4.1 - 1.5.0-1 - 1.5.0.post1 - 1.5.1 - 1.6.0 - 1.6.0.1 - 1.6.2 - 1.6.2.1 - 1.6.2.2 - 1.6.2.3 references: - type: REPORT url: https://github.com/tankywoo/simiki/issues/123 - type: ADVISORY url: https://github.com/advisories/GHSA-fqr5-qphf-vfr8 aliases: - CVE-2020-19000 - GHSA-fqr5-qphf-vfr8 modified: '2021-09-26T23:33:04.295133Z' published: '2021-08-27T19:15:00Z'