Description
XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.
Remediation
References
https://hackerone.com/reports/331110
Related Vulnerabilities
CVE-2020-26259 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2020-11072 Vulnerability in npm package slp-validate
CVE-2021-23386 Vulnerability in npm package dns-packet
CVE-2015-5209 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:io_2.12