Description
Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.
Remediation
References
https://hackerone.com/reports/570563
Related Vulnerabilities
CVE-2022-22143 Vulnerability in npm package convict
CVE-2022-3952 Vulnerability in maven package com.manydesigns:portofino-microservice-launcher
CVE-2021-21631 Vulnerability in maven package org.jenkins-ci.plugins:cloud-stats
CVE-2022-38900 Vulnerability in npm package decode-uri-component
CVE-2022-41915 Vulnerability in maven package io.netty:netty-codec