Description
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NODEREDDASHBOARD-471939
Related Vulnerabilities
CVE-2022-31190 Vulnerability in maven package org.dspace:dspace-xmlui
CVE-2021-46062 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2018-11697 Vulnerability in npm package node-sass
CVE-2021-44585 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.convertors