Description
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0493 | Cross-site Scripting (XSS) in serve-lite |
Github GHSA |
GHSA-j8x7-qcw4-xx85 | Cross-site Scripting (XSS) in serve-lite |
References
History
Tue, 01 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-04-01T14:55:17.127Z
Reserved: 2022-02-24T11:58:25.184Z
Link: CVE-2022-25847
Updated: 2024-08-03T04:49:44.256Z
Status : Modified
Published: 2023-01-26T21:15:30.783
Modified: 2025-04-01T15:15:50.237
Link: CVE-2022-25847
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA