Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g662-qq45-ppwm

Опубликовано: 21 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Smoothie vulnerable to Cross-site Scripting when tooltipLabel or strokeStyle are controlled by users

The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.

Пакеты

Наименование

smoothie

npm
Затронутые версииВерсия исправления

>= 1.31.0, < 1.36.1

1.36.1

EPSS

Процентиль: 65%
0.00501
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 3 лет назад

The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.

EPSS

Процентиль: 65%
0.00501
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79