Description
A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder names.
Remediation
References
https://hackerone.com/reports/319794
Related Vulnerabilities
CVE-2019-17495 Vulnerability in maven package org.webjars.npm:swagger-ui
CVE-2019-18799 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2021-23327 Vulnerability in npm package apexcharts
CVE-2021-25929 Vulnerability in maven package org.opennms:opennms-webapp
CVE-2020-19676 Vulnerability in maven package com.alibaba.nacos:nacos-api