Description
This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).
References
https://snyk.io/vuln/SNYK-JS-FILEUPLOADWITHPREVIEW-1579492
Third Party Advisory
https://snyk.io/vuln/SNYK-JS-FILEUPLOADWITHPREVIEW-1579492
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
4.2 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-09-05T12:15:07.370Z
4 years agoLast modified
2024-11-21T04:51:45.720Z
1 year ago