Stimulsoft Dashboard.JS Cross Site Scripting vulnerability (GHSA-9cgf-pxwq-2cpw)
- Severity:
- Medium
Description
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.
Recommendation
Update the stimulsoft-dashboards-js
package to the latest compatible version. Followings are version details:
- Affected version(s): < 2024.1.2
- Patched version(s): 2024.1.2
References
- GHSA-9cgf-pxwq-2cpw
- cloud-trustit.spp.at
- stimulsoft.com
- cves.at
- CVE-2024-24397
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Regular Expression Denial of Service (ReDoS) in lodash (GHSA-x5rq-j2xg-h7qm) 3 - CVE-2019-1010266
- Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query - CVE-2025-31125
- Prototype pollution vulnerability found in Mermaid's bundled version of DOMPurify - Vulnerability
- thlorenz browserify-shim vulnerable to prototype pollution (GHSA-r737-347m-wqc7) - CVE-2022-37621
- Tags:
- npm
- stimulsoft-dashboards-js
Anything's wrong? Let us know Last updated on March 02, 2024