{"id":"GHSA-393x-fr59-r8fg","summary":"statics-server Cross-site Scripting vulnerability","details":"An XSS in statics-server \u003c= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser. Statics-server does not implement any HTML escaping when displays directory index in the browser. Variable `v` is used in `\u003ca href\u003e` element without escaping, which allows to embed HTML `\u003ciframe\u003e` tag with `src` attribute points to another HTML file in the directory. This file can contain malicious JavaScript code, which will be executed:\n\n```js\n// ./node_modules/statics-server/index.js, line 18:\n\n    if(fs.lstatSync(staticPath).isDirectory()){\n        var files=fs.readdirSync(staticPath);\n        var lis='';\n        files.forEach((v,i)=\u003e{\n            if(fs.lstatSync(path.resolve(staticPath,v)).isDirectory()){\n                lis+=`\u003cli\u003e\u003ca href=\"${req.url}${v}/\"\u003e${v}/\u003c/a\u003e\u003c/li\u003e`;\n            }else {\n                lis+=`\u003cli\u003e\u003ca href=\"${req.url}${v}\"\u003e${v}\u003c/a\u003e\u003c/li\u003e`\n            }\n        });\n\n        (...)\n```","aliases":["CVE-2018-3771"],"modified":"2024-04-22T23:26:36.518156Z","published":"2022-05-13T01:32:20Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-04-22T23:08:32Z","nvd_published_at":"2018-07-20T22:29:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-3771"},{"type":"WEB","url":"https://hackerone.com/reports/355458"}],"affected":[{"package":{"name":"statics-server","ecosystem":"npm","purl":"pkg:npm/statics-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.0.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-393x-fr59-r8fg/GHSA-393x-fr59-r8fg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}