Description
Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.
Remediation
References
https://hackerone.com/reports/570563
Related Vulnerabilities
CVE-2023-37895 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-webapp
CVE-2019-18797 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2020-7605 Vulnerability in npm package gulp-tape
CVE-2023-0835 Vulnerability in npm package markdown-pdf
CVE-2021-46037 Vulnerability in maven package net.mingsoft:ms-mcms