Description
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
Remediation
References
https://github.com/NodeBB/NodeBB/compare/56b79a9...4de7529
https://github.com/NodeBB/NodeBB/pull/3371
https://vulners.com/securityvulns/SECURITYVULNS:DOC:32625
https://www.vulnerability-lab.com/get_content.php?id=1608
Related Vulnerabilities
CVE-2020-10591 Vulnerability in maven package com.walmartlabs.concord.server:concord-server-impl
CVE-2021-42010 Vulnerability in maven package org.apache.heron:heron-api
CVE-2022-35961 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts
CVE-2018-1313 Vulnerability in maven package org.apache.derby:derby
CVE-2018-25007 Vulnerability in maven package com.vaadin:flow-server