Описание
Cross-site Scripting in node-red-dashboard
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.
Пакеты
Наименование
node-red-dashboard
npm
Затронутые версииВерсия исправления
< 2.17.0
2.17.0
Связанные уязвимости
CVSS3: 5.4
nvd
больше 6 лет назад
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.