CVE-2024-47817 - CVE House
Back to Database
Status published Medium CVE-2024-47817

Unvalidated paragraph widget values can be used for Cross-site Scripting in lara-zeus

Vulnerability Description

Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for the lara-zeus ecosystem. If values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a paragraph widget is rendered. Users are advised to upgrade to the appropriate fix versions detailed in the advisory metadata. There are no known workarounds for this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47817

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

dynamic-dashboard
Vulnerable Versions:
lara-zeus/dynamic-dashboard: >= 3.0.0, < 3.0.2, lara-zeus/artemis: >= 1.0.0, < 1.0.7

Timeline

Official Publish: October 7th, 2024
Last Modified: October 8th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)