VYPR
Medium severity5.4OSV Advisory· Published Aug 30, 2024· Updated Jun 17, 2026

CVE-2024-6585

CVE-2024-6585

Description

Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject malicious scripts into vulnerable web pages. A threat actor could potentially exploit this vulnerability to store malicious JavaScript which executes in the context of a user’s session with the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Lightdash/LightdashOSV2 versions
    0.1.0, 0.1.1, 0.1.2, …+ 1 more
    • (no CPE)range: 0.1.0, 0.1.1, 0.1.2, …
    • (no CPE)range: <0.1024.6

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.