Description
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.
Recommendation
Update the stimulsoft-dashboards-js
package to the latest compatible version. Followings are version details:
- Affected version(s): < 2024.1.2
- Patched version(s): 2024.1.2
References
- GHSA-9m6m-c64r-w4f4
- cloud-trustit.spp.at
- stimulsoft.com
- cves.at
- CVE-2024-24396
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Vite's `server.fs` settings were not applied to HTML files - CVE-2025-58752
- Trix editor subject to XSS vulnerabilities on copy & paste - CVE-2024-53847
- Knwl.js Regular Expression Denial of Service vulnerability - CVE-2020-26306
- VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability - CVE-2024-29271
- Tags:
- npm
- stimulsoft-dashboards-js
Anything's wrong? Let us know Last updated on February 14, 2024