The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves.
References
Link | Resource |
---|---|
https://hackerone.com/reports/507159 | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-01-06 09:15
Updated : 2020-01-10 13:01
NVD link : CVE-2019-15602
Mitre link : CVE-2019-15602
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
itwork
- fileview