Описание
Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a paragraph widget is rendered. Users are advised to upgrade to the appropriate fix versions detailed in the advisory metadata. There are no known workarounds for this vulnerability.
EPSS
Процентиль: 29%
0.00104
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
больше 1 года назад
Lara-zeus Dynamic Dashboard and Artemis do not validate paragraph widget values which can be used for XSS
EPSS
Процентиль: 29%
0.00104
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79