Description
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
Remediation
References
https://github.com/scullyio/scully/pull/1182
https://snyk.io/vuln/SNYK-JS-SCULLYIOSCULLY-1055829
Related Vulnerabilities
CVE-2018-9206 Vulnerability in maven package org.webjars.npm:blueimp-file-upload
CVE-2022-39386 Vulnerability in npm package fastify-websocket
CVE-2020-12265 Vulnerability in maven package org.webjars.npm:decompress
CVE-2019-15478 Vulnerability in npm package status-board
CVE-2022-24897 Vulnerability in maven package org.xwiki.commons:xwiki-commons-velocity