The admin panel is subject to potential XSS attach in case an admin assigns a valuator to a proposal, or does any other action that generates an admin activity log where one of the resources has an XSS crafted.
N/A
Redirect the pages /admin and /admin/logs to other admin pages to prevent this access (i.e. /admin/organization/edit)
OWASP ASVS v4.0.3-5.1.3
{
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"nvd_published_at": "2024-09-16T19:16:10Z",
"github_reviewed": true,
"github_reviewed_at": "2024-09-16T17:17:20Z"
}