Vulnerabilities/

Cross-site Scripting (XSS) - Stored in crud-file-server

Severity:
Medium

Description

Versions of crud-file-server before 0.8.0 are vulnerable to stored cross-site scripting (XSS). This is due to insufficient santiziation of filenames when directory index is served by crud-file-server.

Recommendation

Update the crud-file-server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
crud-file-server
Anything's wrong? Let us know Last updated on January 31, 2023

This issue is available in SmartScanner Professional

See Pricing