Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lightangel1412

#47269of 53,633
5.4Total CVSS
Vulnerabilities · 1
PT-2019-17686
5.4
2019-07-30
Unknown · Min-Http-Server · CVE-2019-5457
**Name of the Vulnerable Software and Affected Versions** min-http-server (all versions) **Description** A cross-site scripting (XSS) issue allows an attacker with access to the server file system to execute arbitrary JavaScript code in a victim's browser. The package fails to sanitize filenames, enabling attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code. **Recommendations** For all versions, consider using an alternative package until a fix is made available. As a temporary workaround, consider restricting access to files with potentially malicious names to minimize the risk of exploitation.