Vulnerabilities/

Phishing attack vulnerability by uploading malicious HTML file

Severity:
Medium

Description

Phishing attack vulnerability by uploading malicious files. A malicious user could upload a HTML file to Parse Server via its public API. That HTML file would then be accessible at the internet domain at which Parse Server is hosted. The URL of the the uploaded HTML could be shared for phishing attacks.

Recommendation

Update the parse-server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
parse-server
Anything's wrong? Let us know Last updated on November 05, 2023

This issue is available in SmartScanner Professional

See Pricing