Description
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
Remediation
References
https://github.com/scullyio/scully/pull/1182
https://snyk.io/vuln/SNYK-JS-SCULLYIOSCULLY-1055829
Related Vulnerabilities
CVE-2023-26477 Vulnerability in maven package org.xwiki.platform:xwiki-platform-flamingo-theme-ui
CVE-2019-13127 Vulnerability in maven package org.webjars.bower:mxgraph
CVE-2018-3721 Vulnerability in maven package org.webjars.npm:lodash.mergewith
CVE-2023-33943 Vulnerability in maven package com.liferay:com.liferay.account.admin.web