Safety vulnerability ID: 54625
The information on this page was manually curated by our Cybersecurity Intelligence Team.
An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
Latest version: 4.1.1
A modern, enterprise-ready business intelligence web application
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application