Description
node-red-dashboard contains a cross-site scripting vulnerability. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The attack may be initiated remotely. The issue is patched in version 3.2.0.
Recommendation
Update the node-red-dashboard package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.2.0
- Patched version(s): 3.2.0
References
Related Issues
- Cross-site Scripting in node-red-dashboard - CVE-2019-10756
- x-data-spreadsheet through 1.1.9 vulnerable to Cross-site Scripting - CVE-2022-25646
- materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input - CVE-2022-25349
- Joplin Desktop App vulnerable to Cross-site Scripting - CVE-2022-45598
You might also like:
- Tags:
- npm
- node-red-dashboard
Anything's wrong? Let us know Last updated on February 01, 2023


