Vulnerabilities/

Reflected Cross-Site Scripting in redis-commander

Severity:
Low

Description

Affected versions of redis-commander contain a cross-site scripting vulnerability in the highlighterId paramter of the clipboard.swf component on hosts serving Redis Commander.

Mitigating factors: Flash must be installed / enabled for this to work. The below proof of concept was verified to work using Firefox 57.

Recommendation

Update the redis-commander package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
redis-commander
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing