-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability centers on improper neutralization of the ReportName field. The primary vulnerable function is the ReportName setter that stores unsanitized input. The medium-confidence export function is included based on common XSS patterns in reporting tools where export features reuse untrusted metadata. The PoC specifically demonstrates payload execution through the designer interface, indicating UI rendering paths are vulnerable. Without patch diffs, we infer vulnerable functions based on the attack vector and typical component structure in reporting libraries.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| stimulsoft-dashboards-js | npm | < 2024.1.2 | 2024.1.2 |