CVE-2021-23439

Publication date

2021-09-05 14:10:11

Family

snyk

State

PUBLISHED

Description

This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).