Executive brief
status-board is a Node.js package used to create and display status dashboards. A cross-site scripting vulnerability in the renderJsDashboard() function allows attackers to inject arbitrary JavaScript code that executes in users' browsers, potentially leading to session hijacking, credential theft, or malware distribution.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in the renderJsDashboard() function (CWE-79). The safeDashboard variable is concatenated directly into the HTTP response with insufficient HTML/JavaScript sanitization, allowing user-controlled input to be interpreted as executable code. Attack requires network access and user interaction (victim visiting a malicious link). An attacker can inject JavaScript to steal session cookies, perform actions on behalf of the user, or redirect to phishing pages. A patch was released in version 1.1.82; all earlier versions are affected.
Affected products
- status-board status-board before 1.1.82
Timeline
- 2019-09-23: disclosed: GHSA published
- 2019-08-15: patched: Fix merged in pull request #949