VDB
Sign up
MEDIUM6.1

GHSA-8864-rhmw-5m6f

Status Board vulnerable to Cross-Site Scripting before v1.1.82

Quick fix

GHSA-8864-rhmw-5m6f — status-board: upgrade to the fixed version with the command below.

npm install status-board@1.1.82

Details

Versions of `status-board` prior to 1.1.82 are vulnerable to Cross-Site Scripting. The `renderDashboard()` function concatenates the `safeDashboard` variable to the printed error message with insufficient sanitization. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim's browser.

## Recommendation

Upgrade to version 1.1.82 to receive a patch.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/status-board
Introduced in: 0Fixed in: 1.1.82
Fixnpm install status-board@1.1.82

References