Description
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
Remediation
References
https://hackerone.com/reports/317125
Related Vulnerabilities
CVE-2021-21297 Vulnerability in npm package @node-red/runtime
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-mysql-cdc
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wfs
CVE-2020-28482 Vulnerability in npm package fastify-csrf
CVE-2010-3863 Vulnerability in maven package org.jsecurity:jsecurity