PT-2019-14208 · Facebook · Status Board
Published
2019-08-26
·
Updated
2019-09-23
·
CVE-2019-15479
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Status Board versions prior to 1.1.82
Description
The issue concerns a reflected Cross-Site Scripting (XSS) vulnerability. It is caused by insufficient sanitization of the
safeDashboard variable, which is concatenated to a printed error message by the renderDashboard() function. If the safeDashboard variable is controlled by user input, it allows attackers to execute arbitrary JavaScript in a victim's browser.Recommendations
Upgrade to version 1.1.82 to receive a patch.
As a temporary workaround, consider restricting user input to the
safeDashboard variable until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Status Board