VYPR

Osm Static Maps

by Osm Static Maps Project

CVEs (1)

  • CVE-2020-7749HigOct 20, 2020
    risk 0.43cvss 7.6epss 0.02

    This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as…