Description
Characters in the GET url path are not properly escaped and can be reflected in the server response.
Remediation
References
https://snyk.io/vuln/SNYK-JS-IOBROKERWEB-534971
Related Vulnerabilities
CVE-2020-28281 Vulnerability in npm package set-object-value
CVE-2021-22132 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2021-21119 Vulnerability in npm package electron
CVE-2020-13943 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2021-23331 Vulnerability in maven package com.squareup:connect