Description
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.1.0
References
Related Issues
- materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input - CVE-2022-25349
- wangEditor was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function - CVE-2022-25037
- Reflected cross-site scripting (XSS) vulnerability - CVE-2022-0087
- @braintree/sanitize-url Cross-site Scripting vulnerability - CVE-2022-48345
You might also like:
- Tags:
- npm
- serve-lite
Anything's wrong? Let us know Last updated on January 30, 2023


