Description
XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.
Remediation
References
https://hackerone.com/reports/331110
Related Vulnerabilities
CVE-2018-17244 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2020-7793 Vulnerability in npm package ua-parser-js
CVE-2020-19676 Vulnerability in maven package com.alibaba.nacos:nacos-api
CVE-2019-19771 Vulnerability in npm package fs-extar
CVE-2020-2239 Vulnerability in maven package org.jenkins-ci.plugins:parameterized-remote-trigger