CVE Published: 03/04/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: hackerone |
Vendor: Npm, Inc. |
Product: buttle Status : PUBLISHED
CVE-2019-5422 Description
XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim\'s browser when an attacker creates an arbitrary file on the server.