Description
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.
Remediation
References
https://hackerone.com/reports/681986
Related Vulnerabilities
CVE-2022-39203 Vulnerability in npm package matrix-appservice-irc
CVE-2017-3202 Vulnerability in maven package com.exadel.flamingo.flex:amf-serializer
CVE-2022-31160 Vulnerability in maven package org.fujion.webjars:jquery-ui
CVE-2010-1870 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.13