Description
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
Remediation
References
https://hackerone.com/reports/330356
Related Vulnerabilities
CVE-2023-34981 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2018-3745 Vulnerability in npm package atob
CVE-2023-40572 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2020-28269 Vulnerability in npm package field
CVE-2008-6681 Vulnerability in maven package org.apache.geronimo.plugins:dojo