cve/2024/CVE-2024-6585.md
2025-09-29 21:09:30 +02:00

1.0 KiB
Raw Blame History

CVE-2024-6585

Description

Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject malicious scripts into vulnerable web pages. A threat actor could potentially exploit this vulnerability to store malicious JavaScript which executes in the context of a users session with the application.

POC

Reference

Github