5.10.9
5 years ago
1 months ago
Known vulnerabilities in the org.yamcs:yamcs-web package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when displaying the Telecommands uplinked to the spacecraft. An attacker can trigger the execution of malicious code by setting the Telecommand's name to a malicious JavaScript payload. This is only exploitable if the user navigates to the Archive Browser, zooms in on the timeline to review the Telecommands and hovers the mouse cursor over one of the Telecommands containing the malicious JavaScript. This will display a Tooltip, which will trigger the execution of the malicious code. How to fix Cross-site Scripting (XSS)? Upgrade | [,5.9.3) |