This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-09-05 07:15
Updated : 2021-09-10 12:46
NVD link : CVE-2021-23439
Mitre link : CVE-2021-23439
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
file-upload-with-preview_project
- file-upload-with-preview