Show Sidebar Hide Sidebar

Plotly Security Advisory - XSS in Chart Studio Dashboard Creator

Summary of issue

A Cross-Site Scripting (XSS) vulnerability has been fixed in the Chart Studio Dashboard Creator.

An attacker can trick an unsuspecting user into viewing a specially crafted dashboard, then clicking a certain link. The vulnerability would have allowed the attacker to perform any action using the victim’s credentials on that site.

Thanks to Lucky Sen and Mahmoud Gamal for reporting variations of this issue.

Affected products and versions

Resolution

General notes regarding security reporting

Please send all security reports concerning Plotly products to security@plot.ly.

Return to the main Plotly Security Advisories page