Vulnerabilities/

Stored Cross-Site Scripting in simplehttpserver

Severity:
Medium

Description

Simplehttpserver prior to version 0.1.0 are vulnerable to stored cross-site scripting (XSS). To be exploited an attacker needs to control the filename of a file that is used in the directory listing output. This version is patched in 0.1.0

Recommendation

Update the simplehttpserver package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
simplehttpserver
Anything's wrong? Let us know Last updated on January 31, 2023

This issue is available in SmartScanner Professional

See Pricing