Description
Characters in the GET url path are not properly escaped and can be reflected in the server response.
Remediation
References
https://snyk.io/vuln/SNYK-JS-IOBROKERWEB-534971
Related Vulnerabilities
CVE-2017-15692 Vulnerability in maven package org.apache.geode:geode-core
CVE-2018-1340 Vulnerability in maven package org.apache.guacamole:guacamole
CVE-2020-7702 Vulnerability in npm package templ8
CVE-2018-20059 Vulnerability in maven package ro.pippo:pippo-jaxb
CVE-2022-39299 Vulnerability in npm package @node-saml/node-saml