CVE Database
/

CVE-2024-6585

Back to search

CVE-2024-6585

Published: Aug 30, 2024

Modified: Sep 3, 2024

PUBLISHED

Description

Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject malicious scripts into vulnerable web pages. A threat actor could potentially exploit this vulnerability to store malicious JavaScript which executes in the context of a user’s session with the application.

VendorProductVersions

Lightdash

Lightdash

affected
0.1024.6 - < 0.1042.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now