Vulnerability library
Security checkFebruary 01, 2023

node-red-dashboard vulnerable to Cross-site Scripting

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmnode-red-dashboard

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

node-red-dashboard contains a cross-site scripting vulnerability. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The attack may be initiated remotely. The issue is patched in version 3.2.0.

Recommendation

Update the node-red-dashboard package to the latest compatible version. Followings are version details:

  • Affected version(s): < 3.2.0
  • Patched version(s): 3.2.0

References

Could your website be exposed too?

SmartScanner can check your website for node-red-dashboard vulnerable to Cross-site Scripting and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated February 01, 2023