Description
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
Remediation
References
https://github.com/scullyio/scully/pull/1182
https://snyk.io/vuln/SNYK-JS-SCULLYIOSCULLY-1055829
Related Vulnerabilities
CVE-2023-40582 Vulnerability in npm package find-exec
CVE-2023-49372 Vulnerability in maven package com.jfinal:jfinal
CVE-2022-25912 Vulnerability in npm package simple-git
CVE-2021-43090 Vulnerability in maven package com.predic8:soa-model-parent
CVE-2018-1999020 Vulnerability in maven package org.onosproject:onos-core-common