SB2020010619 - Cross-site scripting in Fileview
Published: January 6, 2020 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site scripting (CVE-ID: CVE-2019-15602)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves.
Remediation
Install update from vendor's website.