Junglewise Threat Intelligence

CVE-2019-15479: Status Board reflected cross-site scripting

CVE-2019-15479 · Severity: low · CVSS 3 · Published 2019-09-23

Vendors: npm.

Executive brief

Status Board is an open-source Node.js dashboard application. Versions before 1.1.82 contain a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into error messages. An attacker could trick a user into clicking a malicious link, causing the injected script to execute in the victim's browser and potentially steal sensitive data or session tokens.

Technical details

The vulnerability is a reflected cross-site scripting (CWE-79) flaw in the renderDashboard() function. The safeDashboard variable is concatenated into a printed error message without sufficient HTML sanitization, allowing user-controlled input to be rendered as JavaScript. The attack vector is network-based and requires user interaction (clicking a malicious link). An attacker can execute arbitrary JavaScript in the victim's browser context. The vulnerability was fixed in version 1.1.82 and patched via pull request #948 on the status-board GitHub repository.

Affected products

  • Status Board status-board before 1.1.82

Timeline

  • 2019-09-23: disclosed: Advisory published
  • 2019-08-15: patched: Fix merged in pull request #948

References

Related threats