Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a paragraph widget is rendered. Users are advised to upgrade to the appropriate fix versions detailed in the advisory metadata. There are no known workarounds for this vulnerability.
History

Tue, 08 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Lara Zeus
Lara Zeus dynamic Dashboard
CPEs cpe:2.3:a:lara_zeus:dynamic_dashboard:*:*:*:*:*:*:*:*
Vendors & Products Lara Zeus
Lara Zeus dynamic Dashboard
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
Description Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a paragraph widget is rendered. Users are advised to upgrade to the appropriate fix versions detailed in the advisory metadata. There are no known workarounds for this vulnerability.
Title Unvalidated paragraph widget values can be used for Cross-site Scripting in lara-zeus
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-07T21:22:18.473Z

Updated: 2024-10-08T14:19:30.748Z

Reserved: 2024-10-03T14:06:12.638Z

Link: CVE-2024-47817

cve-icon Vulnrichment

Updated: 2024-10-08T14:19:20.816Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-07T22:15:03.913

Modified: 2024-10-10T12:57:21.987

Link: CVE-2024-47817

cve-icon Redhat

No data.