Description
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
Remediation
References
https://github.com/zeit/next.js/releases/tag/7.0.2
Related Vulnerabilities
CVE-2022-36922 Vulnerability in maven package org.jenkins-ci.plugins:lucene-search
CVE-2017-12634 Vulnerability in maven package org.apache.camel:camel-castor
CVE-2023-36665 Vulnerability in npm package protobufjs
CVE-2022-39387 Vulnerability in maven package org.xwiki.contrib.oidc:oidc-authenticator
CVE-2016-10735 Vulnerability in maven package com.loopeer.android:bootstrap