GHSA-6m4r-cgm3-6q7q
Dashboard / Vulnerabilities / GHSA-6m4r-cgm3-6q7q
Summary: Cross-Site Scripting in status-board
Details: All versions of `status-board` are vulnerable to Cross-Site Scripting. The `renderJsDashboard()` function concatenates the `safeDashboard` variable to the HTTP response message with insufficient sanitization. If this variable is controlled by user input it may allow attackers to execute arbitrary JavaScript in a victim's browser. ## Recommendation No fix is currently available. Consider using an alternative package until a fix is made available.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-15478, https://github.com/jameswlane/status-board/pull/949, https://github.com/jameswlane/status-board/pull/949/files, https://snyk.io/vuln/SNYK-JS-STATUSBOARD-460293, https://www.npmjs.com/advisories/1151
Affected packages
Package
Name: status-board
Purl: pkg:npm/status-board
Affected ranges
Type: SEMVER
Events:
