Описание
Cross-Site Scripting in highcharts
Versions of highcharts prior to 7.2.2 or 8.1.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize href values and does not restrict URL schemes, allowing attackers to execute arbitrary JavaScript in a victim's browser if they click the link.
Пакеты
Наименование
highcharts
npm
Затронутые версииВерсия исправления
< 7.2.2
7.2.2
Наименование
highcharts
npm
Затронутые версииВерсия исправления
>= 8.0.0, < 8.1.1
8.1.1
8.7 High
CVSS3
Дефекты
CWE-79
8.7 High
CVSS3
Дефекты
CWE-79