{"id":"CVE-2024-47817","aliases":["GHSA-c6cw-g7fc-4gwc"],"url":"https://o3.security/vulnerability/CVE-2024-47817","summary":"Unvalidated paragraph widget values can be used for Cross-site Scripting in lara-zeus","details":"# Summary\nIf values passed to a paragraph widget are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a paragraph widget is rendered.\n\nVersions of dynamic dashboard from v3.0.0 through v3.0.2 are affected.\n\nPlease upgrade to dynamic dashboard [v3.0.2](https://github.com/lara-zeus/dynamic-dashboard/releases/tag/v3.0.2).\n\n# PoC\n>PoC will be published in a few weeks, once developers have had a chance to upgrade their apps.\n\n# Response\nThis vulnerability (in paragraph widget only) was reported by **Raghav Sharma**, who reported the issue and patched the issue during the morning of 05/10/2024. Thank you **Raghav Sharma**.\n\nThe review process concluded the same day at night, which revealed the issue was also present in paragraph widget. This was fixed the same day and dynamic dashboard [v3.0.2](https://github.com/lara-zeus/dynamic-dashboard/releases/tag/v3.0.2) followed.\n\n## Note:\nif you're published the view (blade files), you have to republish them or check the changes on release to update the affected file.\n","published":"2024-10-07T21:22:18.473Z","modified":"2026-08-12T03:51:26.841351302Z","cvss":null,"epss":{"score":0.00395,"percentile":0.33389,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"lara-zeus/dynamic-dashboard","fixedVersion":"3.0.2"},{"ecosystem":"Packagist","name":"lara-zeus/artemis","fixedVersion":"1.0.7"}],"fix":{"url":"https://github.com/lara-zeus/artemis/commit/3a3f9dd8a706af569c5581b20dcfeff91a43b9d9","label":"lara-zeus/artemis@3a3f9dd"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47817.json"},{"type":"ADVISORY","url":"https://github.com/lara-zeus/dynamic-dashboard/security/advisories/GHSA-c6cw-g7fc-4gwc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47817"},{"type":"FIX","url":"https://github.com/lara-zeus/artemis/commit/3a3f9dd8a706af569c5581b20dcfeff91a43b9d9"},{"type":"FIX","url":"https://github.com/lara-zeus/dynamic-dashboard/commit/adfb4b1cdfdaa01299631f0e569ce201a7cc545a"},{"type":"WEB","url":"https://github.com/lara-zeus/artemis/commit/4636f58628d20d3e78ea8514406bd7da94997f2c"},{"type":"PACKAGE","url":"https://github.com/lara-zeus/dynamic-dashboard"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.841351302Z"}}