Smoothie vulnerable to Cross-site Scripting when tooltipLabel or strokeStyle are controlled by users
- Severity:
- Medium
Description
The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.
Recommendation
Update the smoothie package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.31.0, < 1.36.1
- Patched version(s): 1.36.1
References
Related Issues
- grapesjs before 0.19.5 vulnerable to Cross-site Scripting - CVE-2022-21802
- @dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details - CVE-2022-39350
- mxGraph vulnerable to cross-site scripting in setTooltips function - CVE-2022-40440
- node-red-dashboard vulnerable to Cross-site Scripting - CVE-2022-3783
You might also like:
- Tags:
- npm
- smoothie
Anything's wrong? Let us know Last updated on January 30, 2023


