Description
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
Remediation
References
https://hackerone.com/reports/309648
Related Vulnerabilities
CVE-2021-32831 Vulnerability in npm package total.js
CVE-2023-26105 Vulnerability in npm package utilities
CVE-2023-25194 Vulnerability in maven package org.apache.kafka:kafka-clients
CVE-2018-0114 Vulnerability in npm package node-jose
CVE-2023-33544 Vulnerability in maven package io.hawt:hawtio-system