Description
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.
Remediation
References
https://hackerone.com/reports/681986
Related Vulnerabilities
CVE-2022-31777 Vulnerability in maven package org.apache.spark:spark-core_2.12
CVE-2022-43484 Vulnerability in maven package org.terasoluna.gfw:terasoluna-gfw-common
CVE-2021-46036 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2021-25949 Vulnerability in npm package set-getter
CVE-2021-23439 Vulnerability in npm package file-upload-with-preview