VYPR
Medium severity5.4NVD Advisory· Published Jul 29, 2019· Updated Jun 17, 2026

CVE-2019-1020003

CVE-2019-1020003

Description

invenio-records before 1.2.2 allows XSS.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
invenio-recordsPyPI
< 1.0.21.0.2
invenio-recordsPyPI
>= 1.1.0, < 1.1.11.1.1
invenio-recordsPyPI
>= 1.2.0, < 1.2.21.2.2

Affected products

6
  • cpe:2.3:a:inveniosoftware:invenio-records:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:inveniosoftware:invenio-records:*:*:*:*:*:*:*:*range: <=1.0.1
    • cpe:2.3:a:inveniosoftware:invenio-records:1.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:inveniosoftware:invenio-records:1.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:inveniosoftware:invenio-records:1.2.1:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 1.0.2
  • Invenio/invenio-recordsv5
    Range: < 1.2.2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.