Description
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
Remediation
References
https://hackerone.com/reports/330356
Related Vulnerabilities
CVE-2023-46660 Vulnerability in maven package org.jenkins-ci.plugins:zanata
CVE-2022-25167 Vulnerability in maven package org.apache.flume.flume-ng-sources:flume-jms-source
CVE-2022-0086 Vulnerability in npm package uppy
CVE-2017-3165 Vulnerability in maven package org.apache.brooklyn:brooklyn-jsgui
CVE-2020-14967 Vulnerability in maven package org.webjars.npm:jsrsasign