Summary
OctoPrint-BedLevelVisualizer version <= 1.1.1 reflects, in some situations, the content of gcode files in PNotify notifications without sanitization, leading to a Cross-Site Scripting vulnerability.
Impact
An attacker, by convincing the user to print a malicious gcode file, can inject arbitrary JavaScript code into the victim's browser, taking over their OctoPrint session.
Summary
OctoPrint-BedLevelVisualizer version <= 1.1.1 reflects, in some situations, the content of gcode files in PNotify notifications without sanitization, leading to a Cross-Site Scripting vulnerability.
Impact
An attacker, by convincing the user to print a malicious gcode file, can inject arbitrary JavaScript code into the victim's browser, taking over their OctoPrint session.