CVE-2022-3783
Published Oct 31, 2022A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-compo…
Vendor/product archive
3 CVEs tagged to nodered / node-red-dashboard — 0 Critical, 1 High, 1 Medium, 1 Low, 0 Unrated.
A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-compo…
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.