Skip to content

Conversation

@github-actions
Copy link

Vulnerabilities associated with express/4.16.4

BDSA-2024-6188 (HIGH): Express.js web framework is vulnerable to Cross-Site Scripting (XSS) due to the improper handling of user input in the response.redirect() function. This could allow an attacker to execute JavaScript code on the users browser.

Note The attacker must be in control of the input to response.redirect() and the user must click before the redirect occurs.

Click Here To See More Details On Server

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant