Description
The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves.
Remediation
References
https://hackerone.com/reports/507159
Related Vulnerabilities
CVE-2016-10547 Vulnerability in maven package org.webjars.npm:nunjucks
CVE-2022-29577 Vulnerability in maven package org.owasp.antisamy:antisamy
CVE-2023-23936 Vulnerability in maven package org.webjars.npm:undici
CVE-2021-31407 Vulnerability in maven package com.vaadin:flow-server
CVE-2023-49378 Vulnerability in maven package com.jfinal:jfinal