SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-16022

If control over the labels is obtained, script can be injected.

MEDIUM 6.1EPSS 0.91%

Does this matter?

Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.

Description

Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.91% probability · 58th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
morris.js project/morris.js
Source
support@hackerone.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.