Description
The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.
Recommendation
Update the smoothie package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.31.0, < 1.36.1
- Patched version(s): 1.36.1
References
Could your website be exposed too?
SmartScanner can check your website for Smoothie vulnerable to Cross-site Scripting when tooltipLabel or strokeStyle are controlled by users and gives you actionable findings to investigate.
Start a free scanRelated Issues
- grapesjs before 0.19.5 vulnerable to Cross-site Scripting - CVE-2022-21802
- @dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details - CVE-2022-39350
- mxGraph vulnerable to cross-site scripting in setTooltips function - CVE-2022-40440
- node-red-dashboard vulnerable to Cross-site Scripting - CVE-2022-3783


