Vulnerabilities/

Stimulsoft Dashboard.JS directory traversal vulnerability

Severity:
High

Description

Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.3 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.

Recommendation

Update the stimulsoft-dashboards-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
stimulsoft-dashboards-js
Anything's wrong? Let us know Last updated on February 13, 2024

This issue is available in SmartScanner Professional

See Pricing