VulnerabilityModified
CVE-2017-16022
If control over the labels is obtained, script can be injected.
MEDIUM 6.1EPSS 0.91%
Does this matter?
Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.
Description
Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- morris.js project/morris.js
- Source
- support@hackerone.com
References
- https://github.com/morrisjs/morris.js/pull/464Third Party Advisory
- https://nodesecurity.io/advisories/307Third Party Advisory
- https://github.com/morrisjs/morris.js/pull/464Third Party Advisory
- https://nodesecurity.io/advisories/307Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.