Vulnerabilities/

Options structure open to Cross-site Scripting if passed unfiltered

Severity:
High

Description

In Highcharts versions 8 and earlier, the chart options structure was not systematically filtered for XSS vectors. The potential impact was that content from untrusted sources could execute code in the end user’s browser. Especially when using the useHTML flag, HTML string options would be inserted unfiltered directly into the DOM.

Recommendation

Update the highcharts package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
highcharts
Anything's wrong? Let us know Last updated on January 29, 2023

This issue is available in SmartScanner Professional

See Pricing