VYPR

npm package

save-server

pkg:npm/save-server

Vulnerabilities (1)

  • CVE-2020-15135Aug 4, 2020
    affected < 1.0.7fixed 1.0.7

    save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing Dou