Описание
Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.
Уязвимые конфигурации
Одно из
EPSS
5 Medium
CVSS3
4.7 Medium
CVSS3
Дефекты
Связанные уязвимости
Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.
Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.
Express.js minimalist web framework for node. In express < 4.20.0, pas ...
EPSS
5 Medium
CVSS3
4.7 Medium
CVSS3