Description
The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves.
Remediation
References
https://hackerone.com/reports/507159
Related Vulnerabilities
CVE-2020-7757 Vulnerability in npm package droppy
CVE-2021-4133 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2019-19466 Vulnerability in npm package sceditor
CVE-2022-22984 Vulnerability in npm package snyk-gradle-plugin
CVE-2022-41927 Vulnerability in maven package org.xwiki.platform:xwiki-platform-tag-ui