PT-2019-14207 · Geckoboard · Status Board

Cameron Lonsdale

·

Published

2019-08-26

·

Updated

2019-09-23

·

CVE-2019-15478

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Status Board version 1.1.81 status-board versions all
Description The issue is related to Cross-Site Scripting. The renderJsDashboard() function is vulnerable due to insufficient sanitization of the safeDashboard variable. If this variable is controlled by user input, it may allow attackers to execute arbitrary JavaScript in a victim's browser.
Recommendations For Status Board version 1.1.81, consider disabling the renderJsDashboard() function until a patch is available. For status-board all versions, consider using an alternative package until a fix is made available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15478
GHSA-6M4R-CGM3-6Q7Q

Affected Products

Status Board