Description
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0258 | A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc. |
Github GHSA |
GHSA-8w65-xjc5-9w79 | Cross-Site Scripting in node-red |
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/681986 |
|
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-05T00:49:13.677Z
Reserved: 2019-08-26T00:00:00.000Z
Link: CVE-2019-15607
No data.
Status : Modified
Published: 2020-01-28T03:15:10.777
Modified: 2024-11-21T04:29:07.227
Link: CVE-2019-15607
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA