Vulnerabilities/

Cross-Site Scripting in highcharts

Severity:
High

Description

Versions of highcharts prior to 7.2.2 or 8.1.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize href values and does not restrict URL schemes, allowing attackers to execute arbitrary JavaScript in a victim’s browser if they click the link.

Recommendation

Update the highcharts package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
highcharts
Anything's wrong? Let us know Last updated on November 10, 2023

This issue is available in SmartScanner Professional

See Pricing