Описание
billboard.js is vulnerable to XSS during chart option binding
billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.
Пакеты
Наименование
billboard.js
npm
Затронутые версииВерсия исправления
< 3.18.0
3.18.0
Связанные уязвимости
CVSS3: 6.1
nvd
10 дней назад
billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.