Description
The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves.
Remediation
References
https://hackerone.com/reports/507159
Related Vulnerabilities
CVE-2017-16116 Vulnerability in maven package org.webjars.npm:string
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-common
CVE-2022-27952 Vulnerability in npm package payload
CVE-2020-7677 Vulnerability in npm package thenify
CVE-2017-11341 Vulnerability in maven package org.webjars.npm:node-sass