Description
XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.
Remediation
References
https://hackerone.com/reports/331110
Related Vulnerabilities
CVE-2020-8215 Vulnerability in maven package org.webjars.npm:canvas
CVE-2021-27516 Vulnerability in npm package urijs
CVE-2021-40110 Vulnerability in maven package org.apache.james:james-server
CVE-2020-2243 Vulnerability in maven package org.jenkins-ci.plugins:vmanager-plugin
CVE-2023-47320 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web