Описание
Withdrawn Advisory: Home Assistant Frontend XSS Vulnerability
Withdrawn Advisory
This advisory has been withdrawn because we cannot confirm home-assistant-frontend is or was ever published to npm.
Original Description
In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.
Пакеты
Наименование
home-assistant-frontend
npm
Затронутые версииВерсия исправления
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
около 8 лет назад
In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.