Description
node-red-dashboard contains a cross-site scripting vulnerability. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The attack may be initiated remotely. The issue is patched in version 3.2.0.
Recommendation
Update the node-red-dashboard package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.2.0
- Patched version(s): 3.2.0
References
Could your website be exposed too?
SmartScanner can check your website for node-red-dashboard vulnerable to Cross-site Scripting and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-site Scripting in node-red-dashboard - CVE-2019-10756
- x-data-spreadsheet through 1.1.9 vulnerable to Cross-site Scripting - CVE-2022-25646
- materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input - CVE-2022-25349
- Joplin Desktop App vulnerable to Cross-site Scripting - CVE-2022-45598


