Description
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
Remediation
References
https://hackerone.com/reports/330356
Related Vulnerabilities
CVE-2022-21802 Vulnerability in npm package grapesjs
CVE-2017-16017 Vulnerability in npm package sanitize-html
CVE-2020-7703 Vulnerability in npm package nis-utils
CVE-2020-35149 Vulnerability in npm package mquery
CVE-2021-44585 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core