Description
crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
Remediation
References
https://github.com/omphalos/crud-file-server/commit/4155bfe068bf211b49a0b3ffd06e78cbaf1b40fa
https://hackerone.com/reports/311101
Related Vulnerabilities
CVE-2021-43309 Vulnerability in npm package uri-template-lite
CVE-2021-28164 Vulnerability in maven package org.eclipse.jetty:jetty-webapp
CVE-2018-20834 Vulnerability in maven package org.webjars.npm:tar
CVE-2018-3715 Vulnerability in npm package glance
CVE-2021-33611 Vulnerability in maven package org.webjars.bowergithub.vaadin:vaadin-menu-bar