Remote attackers can inject malicious scripts in Lightdash
CVE-2024-6585

Currently unrated

Key Information:

Vendor

Lightdash

Status
Vendor
CVE Published:
30 August 2024

What is CVE-2024-6585?

Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject malicious scripts into vulnerable web pages. A threat actor could potentially exploit this vulnerability to store malicious JavaScript which executes in the context of a user’s session with the application.

Affected Version(s)

Lightdash 0.1024.6

References

Timeline

  • Vulnerability published

Credit

Kenneth Chiong, Mandiant
Kenneth Chiong, Mandiant
.