PT-2019-14207 · Geckoboard · Status Board

Cameron Lonsdale

·

Publicado

2019-08-26

·

Atualizado

2019-09-23

·

CVE-2019-15478

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Status Board version 1.1.81 status-board versions all
Description The issue is related to Cross-Site Scripting. The renderJsDashboard() function is vulnerable due to insufficient sanitization of the safeDashboard variable. If this variable is controlled by user input, it may allow attackers to execute arbitrary JavaScript in a victim's browser.
Recommendations For Status Board version 1.1.81, consider disabling the renderJsDashboard() function until a patch is available. For status-board all versions, consider using an alternative package until a fix is made available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-15478
GHSA-6M4R-CGM3-6Q7Q

Produtos afetados

Status Board