Vulnerabilities/

CSRF vulnerability in save-server

Severity:
Medium

Description

Versions prior to version v1.05 are affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version v1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version.

This is patched by implementing Double submit.

Recommendation

Update the save-server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
save-server
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing