Executive brief
Status Board is an open-source Node.js dashboard application. Versions before 1.1.82 contain a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into error messages. An attacker could trick a user into clicking a malicious link, causing the injected script to execute in the victim's browser and potentially steal sensitive data or session tokens.
Technical details
The vulnerability is a reflected cross-site scripting (CWE-79) flaw in the renderDashboard() function. The safeDashboard variable is concatenated into a printed error message without sufficient HTML sanitization, allowing user-controlled input to be rendered as JavaScript. The attack vector is network-based and requires user interaction (clicking a malicious link). An attacker can execute arbitrary JavaScript in the victim's browser context. The vulnerability was fixed in version 1.1.82 and patched via pull request #948 on the status-board GitHub repository.
Affected products
- Status Board status-board before 1.1.82
Timeline
- 2019-09-23: disclosed: Advisory published
- 2019-08-15: patched: Fix merged in pull request #948