CVE-2019-5458: XSS
Published Jul 30, 2019
·Updated
Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.
Affected Software
8 affected components
Http-file-server Project Http-file-server Node.js=0.1.0
Http-file-server Project Http-file-server Node.js=0.2.0
Http-file-server Project Http-file-server Node.js=0.2.1
Http-file-server Project Http-file-server Node.js=0.2.2
Http-file-server Project Http-file-server Node.js=0.2.3
Http-file-server Project Http-file-server Node.js=0.2.4
Http-file-server Project Http-file-server Node.js=0.2.5
Http-file-server Project Http-file-server Node.js=0.2.6
Event History
Jul 30, 2019
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-5458?
CVE-2019-5458 has a high severity rating due to its potential for executing arbitrary JavaScript code in a victim's browser.
2
How do I fix CVE-2019-5458?
To fix CVE-2019-5458, upgrade your version of http-file-server to a version later than 0.2.6 where the vulnerability is patched.
3
Who is affected by CVE-2019-5458?
CVE-2019-5458 affects all versions of http-file-server prior to 0.2.7.
4
What type of vulnerability is CVE-2019-5458?
CVE-2019-5458 is classified as a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2019-5458?
Attackers with access to the server file system can exploit CVE-2019-5458 to execute arbitrary JavaScript code in victims' browsers.