Description
Characters in the GET url path are not properly escaped and can be reflected in the server response.
Remediation
References
https://snyk.io/vuln/SNYK-JS-IOBROKERWEB-534971
Related Vulnerabilities
CVE-2018-7408 Vulnerability in maven package org.webjars.bower:npm
CVE-2023-3414 Vulnerability in maven package io.jenkins.plugins:servicenow-devops
CVE-2018-16478 Vulnerability in npm package simplehttpserver
CVE-2019-16777 Vulnerability in maven package org.webjars.npm:bin-links
CVE-2021-21320 Vulnerability in npm package matrix-react-sdk