CVE-2022-25929
21.12.2022, 05:15
The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.
Vendor | Product | Version |
---|---|---|
smoothiecharts | smoothie_charts | 1.31.0 ≤ 𝑥 < 1.36.1 |
𝑥
= Vulnerable software versions
References