PT-2024-32828 · Unknown · Lara-Zeus Dynamic Dashboard
Sharmaraghs
·
Published
2024-10-07
·
Updated
2024-10-10
·
CVE-2024-47817
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Lara-zeus Dynamic Dashboard versions 3.0.0 through 3.0.2
Description
The issue arises when invalid values containing specific characters are passed to a paragraph widget, making applications vulnerable to an XSS attack against users who open a page where the paragraph widget is rendered. There are no known workarounds for this vulnerability.
Recommendations
For Lara-zeus Dynamic Dashboard versions 3.0.0 through 3.0.2, upgrade to version 3.0.2 to resolve the issue. After upgrading, if you have published the view (blade files), you need to republish them or check the changes on the release to update the affected file.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lara-Zeus Dynamic Dashboard