Vulnerabilities/

Cross-site Scripting (XSS) in serve-lite

Severity:
Medium

Description

All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
serve-lite
Anything's wrong? Let us know Last updated on January 30, 2023

This issue is available in SmartScanner Professional

See Pricing