Showing 1 vulnerability on this page for dash-html-components

Signals CISA KEV Ransomware Nuclei
npm vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Dash apps vulnerable to Cross-site Scripting

Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package dash-html-components before 2.0.0; versions of the package dash-html-components before 2.0.16 are vulnerable to Cross-site Scripting (XSS) when the href of the a tag is controlled by an adversary. An authenticated attacker who stores a view that exploits this vulnerability could steal the data that's visible to

CWE-79Feb 2, 20241 related artifact
CVSS-v4.0EPSS1.47%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX