Vulnerabilities/

Stored XSS in TimelineJS3

Severity:
High

Description

TimelineJS renders some user data as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON configuration file.

Most TimelineJS users configure their timeline with a Google Sheets document.

Recommendation

Update the @knight-lab/timelinejs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@knight-lab/timelinejs
Anything's wrong? Let us know Last updated on January 09, 2023