ZeroHour

CVE-2022-25929

PoC ×3
CVSS 3.1
5.4 medium
EPSS
<1%p55
Published
()
Modified
Description

The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.

Vendors
smoothiecharts
Products
smoothie charts
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.