GHSA-754x-4jwp-cqp6
HIGHCVE-2019-15600All versions of httpserver are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code.
- Affected
- <= 1.0.12
- Fixed in
- not stated
- Weakness
- CWE-22
- Published
- 2020-03-31
- Source
- github