Junglewise Threat Intelligence

CVE-2024-24397: Stimulsoft Dashboard.JS cross-site scripting in ReportName field

CVE-2024-24397 · Severity: low · CVSS 3.1 · Published 2024-02-05

Technologies: Stimulsoft Dashboard.JS, stimulsoft-dashboards-js (npm). Vendors: Stimulsoft, npm.

Executive brief

Stimulsoft Dashboard.JS is a JavaScript library used to embed interactive dashboards and reports in web applications. A cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious code through the ReportName field, enabling them to execute arbitrary JavaScript in other users' browsers and potentially steal session data or redirect them to malicious sites.

Technical details

This is a stored or reflected cross-site scripting (CWE-79) vulnerability in the ReportName field of Stimulsoft Dashboard.JS versions before 2024.1.2. The vulnerability allows an authenticated attacker to craft a payload containing JavaScript code that is not properly sanitized before being rendered in the application. The attack requires login credentials and user interaction (a victim must view the crafted report), but when successful allows execution of arbitrary JavaScript in the victim's browser with the ability to steal credentials, modify page content, or perform actions on behalf of the victim. The vulnerability is fixed in version 2024.1.2 and later.

Affected products

  • Stimulsoft Dashboard.JS before 2024.1.2

Timeline

  • 2024-02-05: disclosed
  • 2024-01-01: patched: Fixed in version 2024.1.2

References

Related threats