Description
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
Remediation
References
https://hackerone.com/reports/330356
Related Vulnerabilities
CVE-2023-37914 Vulnerability in maven package org.xwiki.platform:xwiki-platform-invitation-ui
CVE-2021-23497 Vulnerability in npm package @strikeentco/set
CVE-2021-28099 Vulnerability in maven package com.netflix.hollow:hollow
CVE-2023-22491 Vulnerability in npm package gatsby-transformer-remark
CVE-2020-28479 Vulnerability in maven package org.webjars.npm:jointjs