CVE-2024-47817 – lara-zeus/dynamic-dashboard
Package
Manager: composer
Name: lara-zeus/dynamic-dashboard
Vulnerable Version: >=3.0.0 <3.0.2
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
EPSS: 0.00038 pctl0.10147
Details
Lara-zeus Dynamic Dashboard and Artemis do not validate paragraph widget values which can be used for XSS # Summary If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a paragraph widget is rendered. Versions of dynamic dashboard from v3.0.0 through v3.0.2 are affected. Please upgrade to dynamic dashboard [v3.0.2](https://github.com/lara-zeus/dynamic-dashboard/releases/tag/v3.0.2). # PoC >PoC will be published in a few weeks, once developers have had a chance to upgrade their apps. # Response This vulnerability (in paragraph widget only) was reported by **Raghav Sharma**, who reported the issue and patched the issue during the morning of 05/10/2024. Thank you **Raghav Sharma**. The review process concluded the same day at night, which revealed the issue was also present in paragraph widget. This was fixed the same day and dynamic dashboard [v3.0.2](https://github.com/lara-zeus/dynamic-dashboard/releases/tag/v3.0.2) followed. ## Note: if you're published the view (blade files), you have to republish them or check the changes on release to update the affected file.
Metadata
Created: 2024-10-07T14:55:30Z
Modified: 2024-10-08T14:18:39Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-c6cw-g7fc-4gwc/GHSA-c6cw-g7fc-4gwc.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-c6cw-g7fc-4gwc
Finding: F008
Auto approve: 1