GHSA-r96p-v3cr-gfv8
HIGHCVE-2020-28470This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
- Affected
- < 1.0.9
- Fixed in
- 1.0.9
- Weakness
- CWE-79
- Published
- 2021-04-13
- Source
- github