cesanta.mongoose is vulnerable to Cross-Site Scripting (XSS)
54
Medium Risk
When directory listing is enabled, the request path is URL-decoded and written into the listing page title and heading without HTML-entity encoding. A crafted link whose path contains markup causes that markup to execute in the browser of a user who follows it. This reflected cross-site scripting runs in the origin of the Mongoose server and needs no write access. The fix HTML-escapes the decoded path before rendering.
You are affected if you are using a version that falls within the vulnerable range and you serve directory listings with MG_ENABLE_DIRLIST enabled.
cesanta.mongoose is vulnerable to Cross-Site Scripting (XSS) in versions 7.0.0 - 7.21.0.
Upgrade the cesanta.mongoose library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant