CVE

CVE-2020-28470

CVE-2020-28470

This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.

Source: CVE-2020-28470

Exit mobile version