Description
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
Remediation
References
https://hackerone.com/reports/317125
Related Vulnerabilities
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-debug-jdk15on
CVE-2022-24846 Vulnerability in maven package org.geowebcache:gwc-diskquota-jdbc
CVE-2023-26111 Vulnerability in npm package @nubosoftware/node-static
CVE-2023-41900 Vulnerability in maven package org.eclipse.jetty:jetty-openid