Description
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
Remediation
References
https://github.com/scullyio/scully/pull/1182
https://snyk.io/vuln/SNYK-JS-SCULLYIOSCULLY-1055829
Related Vulnerabilities
CVE-2021-41580 Vulnerability in npm package passport-oauth2
CVE-2017-16226 Vulnerability in maven package org.webjars.npm:static-eval
CVE-2021-26814 Vulnerability in npm package wazuh
CVE-2022-31147 Vulnerability in maven package org.webjars:jquery-validation
CVE-2023-30516 Vulnerability in maven package org.jenkins-ci.plugins:image-tag-parameter