Description
Characters in the GET url path are not properly escaped and can be reflected in the server response.
Remediation
References
https://snyk.io/vuln/SNYK-JS-IOBROKERWEB-534971
Related Vulnerabilities
CVE-2023-42399 Vulnerability in maven package org.webjars.npm:jodit
CVE-2020-7762 Vulnerability in npm package jsreport-chrome-pdf
CVE-2013-4317 Vulnerability in maven package org.apache.cloudstack:cloudstack
CVE-2019-10387 Vulnerability in maven package com.xebialabs.xlt.ci:xltestview-plugin
CVE-2016-10677 Vulnerability in npm package google-closure-tools-latest