MEDIUM6.1
GHSA-6m4r-cgm3-6q7q
Cross-Site Scripting in status-board
Quick fix
GHSA-6m4r-cgm3-6q7q — status-board: upgrade to the fixed version with the command below.
npm install status-board@1.1.82Details
All versions of `status-board` are vulnerable to Cross-Site Scripting. The `renderJsDashboard()` function concatenates the `safeDashboard` variable to the HTTP response message with insufficient sanitization. If this variable is controlled by user input it may allow attackers to execute arbitrary JavaScript in a victim's browser.
## Recommendation
No fix is currently available. Consider using an alternative package until a fix is made available.
Are you affected?
Enter the version of the package you're using.