Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15092

Опубликовано: 09 июл. 2020
Источник: nvd
CVSS3: 7.2
CVSS3: 4.8
CVSS2: 3.5
EPSS Низкий

Описание

In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON configuration file. Most TimelineJS users configure their timeline with a Google Sheets document. Those users are exposed to this vulnerability if they grant write access to the document to a malicious inside attacker, if the access of a trusted user is compromised, or if they grant public write access to the document. Some TimelineJS users configure their timeline with a JSON document. Those users are exposed to this vulnerability if they grant write access to the document to a malicious inside attacker, if the access of a trusted user is compromised, or if write access to the system hosting that document is otherwise compromised. Version 3.7.0 of TimelineJS addresses this in two ways. For content which is intended

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:northwestern:timelinejs:*:*:*:*:*:*:*:*
Версия до 3.7.0 (исключая)

EPSS

Процентиль: 79%
0.01315
Низкий

7.2 High

CVSS3

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 7.2
github
больше 5 лет назад

Stored XSS in TimelineJS3

EPSS

Процентиль: 79%
0.01315
Низкий

7.2 High

CVSS3

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79