Description
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
Remediation
References
https://github.com/scullyio/scully/pull/1182
https://snyk.io/vuln/SNYK-JS-SCULLYIOSCULLY-1055829
Related Vulnerabilities
CVE-2016-10735 Vulnerability in maven package com.loopeer.android:bootstrap
CVE-2023-46233 Vulnerability in maven package org.webjars.bowergithub.brix:crypto-js
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core-war
CVE-2017-1000188 Vulnerability in maven package org.webjars.npm:ejs
CVE-2016-6796 Vulnerability in maven package org.apache.tomcat:tomcat-jasper