Description
Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.
Remediation
References
https://hackerone.com/reports/570568
Related Vulnerabilities
CVE-2020-28439 Vulnerability in npm package corenlp-js-prefab
CVE-2023-25767 Vulnerability in maven package org.jenkins-ci.plugins:azure-credentials
CVE-2022-32065 Vulnerability in maven package com.ruoyi:ruoyi
CVE-2023-26487 Vulnerability in npm package vega
CVE-2022-23620 Vulnerability in maven package org.xwiki.platform:xwiki-platform-skin-skinx