Cross-site Scripting (XSS) Affecting simplehttpserver package, versions *


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Mature
EPSS
0.06% (26th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDnpm:simplehttpserver:20180226
  • published6 Mar 2018
  • disclosed26 Feb 2018
  • creditRafal Janicki (bl4de)

Introduced: 26 Feb 2018

CVE-2018-3716  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

There is no fix version for simplehttpserver and this package was removed from npm.

Overview

simplehttpserver is simple imitation of python's SimpleHTTPServer and intended for testing, development and debugging purposes.

Affected versions of this package are vulnerable to Cross-Site Scripting (XSS). It allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript.

Details

<>

References

CVSS Scores

version 3.1