Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page.
| Software | From | Fixed in |
|---|---|---|
| linuxserver / heimdall_application_dashboard | - | 2.5.4.x |