PT-2019-14207 · Geckoboard · Status Board
Cameron Lonsdale
·
Published
2019-08-26
·
Updated
2019-09-23
·
CVE-2019-15478
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Status Board version 1.1.81
status-board versions all
Description
The issue is related to Cross-Site Scripting. The
renderJsDashboard() function is vulnerable due to insufficient sanitization of the safeDashboard variable. If this variable is controlled by user input, it may allow attackers to execute arbitrary JavaScript in a victim's browser.Recommendations
For Status Board version 1.1.81, consider disabling the
renderJsDashboard() function until a patch is available.
For status-board all versions, consider using an alternative package until a fix is made available.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Status Board