The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboards can inject JavaScript code into the dashboard name which will be executed when the website is loaded.
- https://www.first.org/cvss/calculator/3.1
- https://github.com/fkie-cad/nvd-json-data-feeds