Junglewise Threat Intelligence

CVE-2024-24396: Stimulsoft Dashboard.JS cross-site scripting in search bar

CVE-2024-24396 · Severity: low · CVSS 3.1 · Published 2024-02-05

Technologies: Stimulsoft Dashboard.JS, stimulsoft-dashboards-js (npm). Vendors: Stimulsoft, npm.

Executive brief

Stimulsoft Dashboard.JS is a JavaScript library used to embed interactive data dashboards in web applications. A cross-site scripting (XSS) vulnerability in the search bar component allows remote attackers to inject malicious scripts that execute in users' browsers, potentially compromising user sessions or stealing sensitive data displayed in the dashboard.

Technical details

A cross-site scripting (CWE-79) vulnerability exists in the search bar component of Stimulsoft Dashboard.JS prior to version 2024.1.2. The vulnerability is triggered by a crafted payload submitted to the search bar, which is not properly sanitized before being rendered in the browser. The attack requires no authentication and can be exploited via a network connection if a user interacts with a malicious link or content on a page containing the vulnerable component. An attacker can achieve arbitrary code execution within the victim's browser context, enabling session hijacking, credential theft, or malware delivery. The vulnerability was patched in version 2024.1.2.

Affected products

  • Stimulsoft Dashboard.JS before 2024.1.2

Timeline

  • 2024-02-05: disclosed

References

Related threats