Cross-site Scripting (XSS) - Stored in crud-file-server
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Jul 18, 2018 
          to the GitHub Advisory Database
          •
          Updated Jan 31, 2023 
      
  
Description
        Published by the National Vulnerability Database
      Jun 7, 2018 
    
  
        Published to the GitHub Advisory Database
      Jul 18, 2018 
    
  
        Reviewed
      Jun 16, 2020 
    
  
        Last updated
      Jan 31, 2023 
    
  
Versions of
crud-file-serverbefore 0.8.0 are vulnerable to stored cross-site scripting (XSS). This is due to insufficient santiziation of filenames when directory index is served bycrud-file-server.Recommendation
Update to version 0.8.0 or later.
References