cesanta.mongoose is vulnerable to Cross-Site Scripting (XSS)
54
Medium Risk
When directory listing is enabled, filenames are placed into the listing link text without HTML-entity encoding while only the link target is URL-encoded. A file whose name contains markup causes that markup to execute when any user views the listing. This stored cross-site scripting runs in the origin of the Mongoose server. The fix HTML-escapes filenames before rendering them.
You are affected if you are using a version that falls within the vulnerable range and you serve directory listings with MG_ENABLE_DIRLIST enabled and untrusted input can create filenames in the served directory.
cesanta.mongoose is vulnerable to Cross-Site Scripting (XSS) in versions 7.0 - 7.21.
Upgrade the cesanta.mongoose library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant