Vulnerabilities/

Status Board vulnerable to Cross-Site Scripting before v1.1.82

Severity:
Medium

Description

Versions of status-board prior to 1.1.82 are vulnerable to Cross-Site Scripting. The renderDashboard() function concatenates the safeDashboard variable to the printed error message with insufficient sanitization. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim’s browser.

Recommendation

Update the status-board package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
status-board
Anything's wrong? Let us know Last updated on March 31, 2023

This issue is available in SmartScanner Professional

See Pricing