Description
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
Remediation
References
Related Vulnerabilities
WordPress Plugin Efence Multiple Cross-Site Scripting Vulnerabilities (1.3.2)
osTicket Other Vulnerability (CVE-2005-1436)
WordPress Plugin GSEOR-WordPress SEO SQL Injection (1.3)
Jboss EAP Improper Access Control Vulnerability (CVE-2013-4213)
WordPress Plugin Checkout Field Editor for WooCommerce (Pro) Arbitrary File Deletion (3.6.2)