VYPR

save-server

by Neztore

npm: save-server

CVEs (1)

  • CVE-2020-15135Aug 4, 2020
    risk 0.00cvss epss 0.01

    save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing…