MEDIUM6.1
GHSA-89q5-mj78-pw5w
Cross-site Scripting in pekeupload
Details
This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/pekeupload
Introduced in:
0No fixed version published yet for pekeupload (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23673[ADVISORY]
- https://github.com/moxiecode/plupload[PACKAGE]
- https://github.com/moxiecode/plupload/blob/120cc0b5dd3373d7181fd11b06ac2557c890d3f0/js/jquery.plupload.queue/jquery.plupload.queue.js%23L226[WEB]
- https://snyk.io/vuln/SNYK-JS-PEKEUPLOAD-1584360[WEB]