-
Notifications
You must be signed in to change notification settings - Fork 2.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added CVE-2024-21485 Template #11502
base: main
Are you sure you want to change the base?
Conversation
Hi @eeche Thanks for sharing the template with the community and contributing to the template project i have made some minor changes to the template, let me know if it works well at your end Thanks |
|
Hi @eeche can you share a setup instructions to set-up a vulnerable environment and test this vulnerability ? Looking forward to hear back from you Thanks |
|
Hi @eeche Thanks for sharing the details 😄 |
Template / PR Information
Template Validation
I've validated this template locally?
Additional Details (leave it blank if not applicable)
Dash framework versions before 2.15.0 are vulnerable to Cross-site Scripting (XSS)
via href attribute in anchor tags. This template tests for javascript:alert payload injection.
Additional References: