Description This affects the package gsap before 3.6.0. Remediation References CVE-2020-28478 Related Vulnerabilities WordPress Plugin Twitter LiveBlog Cross-Site Request Forgery (1.1.2) Dotclear Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2016-9891) PostgreSQL Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2021-3393) WordPress Plugin Customer Reviews for WooCommerce Cross-Site Scripting (5.16.0) WordPress Plugin Post SMTP-WP SMTP with Email Logs & Mobile App for Failure Alerts-Any SMTP Plus Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES, Postmark Server-Side Request Forgery (2.1.6) Severity High Classification CVE-2020-28478 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Tags Missing Update Known Vulnerabilities