Vulnerabilities/

Cross-site Scripting in file-upload-with-preview

Severity:
Medium

Description

This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).

Recommendation

Update the file-upload-with-preview package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
file-upload-with-preview
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing