ZeroHour

CVE-2020-28487

PoC ×3
CVSS 3.1
6.8 medium
EPSS
1%p72
Published
()
Modified
Description

This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.

Vendors
visjs
Products
vis-timeline
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.