Description
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.1.0
References
Related Issues
- materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input - CVE-2022-25349
- tagify can pass a malicious placeholder to initiate the cross-site scripting (XSS) payload - CVE-2022-25854
- Cross-site Scripting in vditor - CVE-2022-0350
- Cross-site Scripting in Auth0 Lock - CVE-2022-29172
- Tags:
- npm
- serve-lite
Anything's wrong? Let us know Last updated on January 30, 2023