Back to search
CVE-2019-15607
Published: Jan 28, 2020
Modified: Aug 5, 2024
PUBLISHED
Description
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.
| Vendor | Product | Versions |
|---|---|---|
n/a | node-red | affected 0.20.7 and earlier |
Weaknesses (CWE)
References
https://hackerone.com/reports/681986
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now