Description
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
Remediation
References
https://github.com/zeit/next.js/releases/tag/7.0.2
Related Vulnerabilities
CVE-2019-10298 Vulnerability in maven package org.jenkins-ci.plugins:koji
CVE-2019-1003081 Vulnerability in maven package org.jenkins-ci.plugins:openshift-deployer
CVE-2020-16017 Vulnerability in npm package electron
CVE-2023-49374 Vulnerability in maven package com.jfinal:jfinal
CVE-2017-12625 Vulnerability in maven package org.apache.hive.hcatalog:hive-hcatalog-core