Description
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
Remediation
References
https://hackerone.com/reports/317125
Related Vulnerabilities
CVE-2022-35915 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts
CVE-2023-35839 Vulnerability in maven package org.noear:solon.serialization.hessian
CVE-2022-25885 Vulnerability in npm package muhammara
CVE-2020-7649 Vulnerability in npm package snyk-broker
CVE-2023-49448 Vulnerability in maven package com.jfinal:jfinal