Vulnerabilities/

Cross-site Scripting in pekeupload

Severity:
Medium

Description

This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
pekeupload
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing