Description
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
Remediation
References
Related Vulnerabilities
WordPress Plugin Note Press SQL Injection (0.1.1)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-9788)
WordPress Plugin iThemes Security (formerly Better WP Security) Unspecified Vulnerability (6.9.0)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.33)
OpenSSL Resource Management Errors Vulnerability (CVE-2008-1678)