Description
XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.
Remediation
References
https://hackerone.com/reports/331110
Related Vulnerabilities
CVE-2020-7623 Vulnerability in npm package jscover
CVE-2021-46704 Vulnerability in npm package genieacs
CVE-2019-11405 Vulnerability in maven package org.openapitools:openapi-generator-project
CVE-2017-3156 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-oauth2
CVE-2023-37964 Vulnerability in maven package org.jenkins-ci.plugins:elasticbox