QID 981075
QID 981075: Nodejs (npm) Security Update for @ckeditor/ckeditor5-link (GHSA-gvpx-9459-w3mj)
Versions of `status-board` prior to 10.0.1 are vulnerable to Cross-Site Scripting. The `_createPreviewButton()` function fails to sanitize the `href` attribute of a created `<a>` tag. This may allow attackers to execute arbitrary JavaScript in a victim's browser.
## Recommendation
Upgrade to version 10.0.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gvpx-9459-w3mj for updates pertaining to this vulnerability.
Vendor References
- GHSA-gvpx-9459-w3mj -
github.com/advisories/GHSA-gvpx-9459-w3mj
CVEs related to QID 981075
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gvpx-9459-w3mj | @ckeditor/ckeditor5-link |
|