CVE-2022-25929

The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:smoothiecharts:smoothie_charts:*:*:*:*:*:node.js:*:*

Information

Published : 2022-12-20 21:15

Updated : 2022-12-27 14:43


NVD link : CVE-2022-25929

Mitre link : CVE-2022-25929


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

smoothiecharts

  • smoothie_charts