Description
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
Remediation
References
https://github.com/scullyio/scully/pull/1182
https://snyk.io/vuln/SNYK-JS-SCULLYIOSCULLY-1055829
Related Vulnerabilities
CVE-2018-1000613 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2022-4942 Vulnerability in npm package eslint-detailed-reporter
CVE-2019-25155 Vulnerability in maven package org.webjars.bower:dompurify
CVE-2011-2093 Vulnerability in maven package com.adobe.blazeds:flex-messaging-common
CVE-2021-21175 Vulnerability in maven package org.webjars.npm:electron