Description
Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.1.0
References
Related Issues
- NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability - CVE-2023-45884
- Vega has Cross-site Scripting vulnerability in `lassoAppend` function - CVE-2023-26487
- Vega has Cross-site Scripting vulnerability in `lassoAppend` function - vega - CVE-2023-26487
- Joplin Cross-site Scripting vulnerability - joplin - CVE-2023-37298
You might also like:
- Tags:
- npm
- openmct
Anything's wrong? Let us know Last updated on November 22, 2023


