Launchpad.net

CVE 2019-5458

Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.

See the CVE page on Mitre.org for more details.

References