Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The dashboard builds log entries with string concatenation and assigns them to innerHTML using unescaped log.message/log.raw values. If any attacker-controlled input reaches the logs, visiting the dashboard can trigger stored XSS in the browser of anyone viewing the page, which is especially dangerous in an observability tool that may be used by privileged operators.
