CVE-2024-6585

CVSS V2 None CVSS V3 None
Description
Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject malicious scripts into vulnerable web pages. A threat actor could potentially exploit this vulnerability to store malicious JavaScript which executes in the context of a user’s session with the application.
Overview
  • CVE ID
  • CVE-2024-6585
  • Assigner
  • Mandiant
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-08-30T22:17:28.565Z
  • Last Modified Date
  • 2024-08-30T22:20:44.647Z
History
Created Old Value New Value Data Type Notes
2024-08-31 13:05:16 Added to TrackCVE