Description
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.
Remediation
References
https://hackerone.com/reports/681986
Related Vulnerabilities
CVE-2018-19907 Vulnerability in maven package org.craftercms:crafter-engine
CVE-2022-25646 Vulnerability in npm package x-data-spreadsheet
CVE-2018-19056 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2022-41704 Vulnerability in maven package org.apache.xmlgraphics:batik-bridge
CVE-2020-26245 Vulnerability in npm package systeminformation