VDB
Sign up
MEDIUM6.1

GHSA-h24f-9mm4-w336

Cross-site Scripting (XSS) - Stored in crud-file-server

Quick fix

GHSA-h24f-9mm4-w336 — crud-file-server: upgrade to the fixed version with the command below.

npm install crud-file-server@0.8.0

Details

Versions of `crud-file-server` before 0.8.0 are vulnerable to stored cross-site scripting (XSS). This is due to insufficient santiziation of filenames when directory index is served by `crud-file-server`.

## Recommendation

Update to version 0.8.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/crud-file-server
Introduced in: 0Fixed in: 0.8.0
Fixnpm install crud-file-server@0.8.0

References