### [CVE-2018-3771](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3771) ![](https://img.shields.io/static/v1?label=Product&message=statics-server&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Cross-site%20Scripting%20(XSS)%20-%20Generic%20(CWE-79)&color=brighgreen) ### Description An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser. ### POC #### Reference - https://hackerone.com/reports/355458 - https://hackerone.com/reports/355458 #### Github No PoCs found on GitHub currently.