Loading HuntDB...

GHSA-h5pq-x44c-mx4p

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function which will be executed when the widget receives data from its data source.

Related CVEs

Key Information

GHSA ID
GHSA-h5pq-x44c-mx4p
Published
June 12, 2025 3:31 PM
Last Modified
June 12, 2025 3:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 14, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.