Description
XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.
Remediation
References
https://hackerone.com/reports/331110
Related Vulnerabilities
CVE-2020-7755 Vulnerability in npm package dat.gui
CVE-2022-28158 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest
CVE-2021-32859 Vulnerability in npm package baremetrics-calendar
CVE-2022-25842 Vulnerability in maven package com.alibaba.oneagent:one-java-agent-plugin
CVE-2022-21803 Vulnerability in maven package org.webjars.npm:nconf