Plotly Security Advisory - XSS in Plotly Dashboard Creator
Summary of issue
A Cross-Site Scripting (XSS) vulnerability has been fixed in the Plotly Dashboard Creator.
An attacker can trick an unsuspecting user into viewing a specially crafted dashboard, then clicking a certain link. The vulnerability would have allowed the attacker to perform any action using the victim’s credentials on that site.
Thanks to Lucky Sen and Mahmoud Gamal for reporting variations of this issue.
Affected products and versions
- Plotly On-Premise version 2.0.0 through 2.1.0.
- This issue has been fixed in Plotly On-Premise version 2.1.1, which is available as a free upgrade to all Plotly On-Premise customers.
- The issue was fixed in Plotly Cloud on 2017-01-18.
General notes regarding security reporting
Please send all security reports concerning Plotly security products to firstname.lastname@example.org.
Return to the main Plotly Security Advisories page