Description
All versions of graylog-web-interface are vulnerable to Cross-Site Scripting (XSS). The package fails to escape output on the TypeAhead and QueryInput components, which may allow attackers to execute arbitrary JavaScript on the victim’s browser.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0.0.0
References
Related Issues
- Cross-site scripting vulnerability in TinyMCE - tinymce - GHSA-27gm-ghr9-4v95 - CVE-2020-17480
- iziModal Cross-site Scripting vulnerability - CVE-2021-32860
- CKEditor4 low-risk cross-site scripting (XSS) vulnerability linked to potential domain takeover - CVE-2024-43411
- Glossarizer Cross-site Scripting vulnerability - CVE-2024-42515
You might also like:
- Tags:
- npm
- graylog-web-interface
Anything's wrong? Let us know Last updated on January 09, 2023


