GHSA-v8fc-qxvj-f3mg, CVE-2023-45885
npm/openmct
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.
All versions up to 3.1.0
Unfortunately, there is no solution available yet.
2023-11-17
source |