Description
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
Remediation
References
https://github.com/scullyio/scully/pull/1182
https://snyk.io/vuln/SNYK-JS-SCULLYIOSCULLY-1055829
Related Vulnerabilities
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wfs
CVE-2019-8331 Vulnerability in maven package org.webjars.npm:bootstrap
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2020-7750 Vulnerability in npm package scratch-svg-renderer
CVE-2022-24823 Vulnerability in maven package io.netty:netty-codec-http