QID 984025
QID 984025: Nodejs (npm) Security Update for sexstatic (GHSA-qfh2-6f7q-gr86)
All versions of `sexstatic` are vulnerable to stored cross-site scripting (xss). This is exploitable if an attacker can control a filename that is served by `sexstatic`. ## Recommendation As there is no fix is currently available for this vulnerability it is our recommendation to not install or used this module at this time.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qfh2-6f7q-gr86 for updates pertaining to this vulnerability.
Vendor References
- GHSA-qfh2-6f7q-gr86 -
github.com/advisories/GHSA-qfh2-6f7q-gr86
CVEs related to QID 984025
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qfh2-6f7q-gr86 | sexstatic |
|