Description
An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.
Remediation
References
https://hackerone.com/reports/355458
Related Vulnerabilities
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core-rs
CVE-2022-45208 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system
CVE-2018-9207 Vulnerability in npm package jquery-file-upload
CVE-2015-8315 Vulnerability in npm package ms
CVE-2023-47327 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web