Description
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NODEREDDASHBOARD-471939
Related Vulnerabilities
CVE-2023-30548 Vulnerability in npm package gatsby-plugin-sharp
CVE-2018-3739 Vulnerability in npm package https-proxy-agent
CVE-2017-16220 Vulnerability in npm package wind-mvc
CVE-2017-20162 Vulnerability in maven package org.webjars.npm:ms
CVE-2020-14967 Vulnerability in maven package org.webjars.bower:jsrsasign