Description
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
Remediation
References
https://hackerone.com/reports/330356
Related Vulnerabilities
CVE-2022-45400 Vulnerability in maven package org.jvnet.hudson.plugins:japex
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2020-28279 Vulnerability in npm package flattenizer
CVE-2022-37223 Vulnerability in maven package com.jflyfox:jflyfox_jfinal
CVE-2020-28469 Vulnerability in maven package org.webjars.npm:glob-parent