Description
Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin Panel.
Remediation
References
https://devhub.checkmarx.com/cve-details/cve-2023-46499/
https://devhub.checkmarx.com/cve-details/Cx0f8b38be-d5de/
Related Vulnerabilities
CVE-2012-5817 Vulnerability in maven package org.codehaus.xfire:xfire-core
CVE-2022-25927 Vulnerability in maven package org.webjars.npm:ua-parser-js
CVE-2022-25171 Vulnerability in npm package p4
CVE-2020-2222 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-45390 Vulnerability in maven package io.loader:loaderio-jenkins-plugin