CVE-2019-10756
08.10.2019, 19:15
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.
Vendor | Product | Version |
---|---|---|
nodered | node-red-dashboard | 𝑥 < 2.17.0 |
𝑥
= Vulnerable software versions