It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://snyk.io/vuln/SNYK-JS-NODEREDDASHBOARD-471939 | 
                     | 
            
History
                    No history.
Status: PUBLISHED
Assigner: snyk
Published: 2019-10-08T18:58:18
Updated: 2024-08-04T22:32:01.593Z
Reserved: 2019-04-03T00:00:00
Link: CVE-2019-10756
No data.
Status : Modified
Published: 2019-10-08T19:15:09.823
Modified: 2024-11-21T04:19:51.640
Link: CVE-2019-10756
No data.