Description
An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.
Remediation
References
https://hackerone.com/reports/355458
Related Vulnerabilities
CVE-2023-26474 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2020-26238 Vulnerability in maven package com.cronutils:cron-utils
CVE-2023-38507 Vulnerability in npm package @strapi/plugin-users-permissions
CVE-2023-38905 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core