CVE Database
/

CVE-2017-16022

Back to search

CVE-2017-16022

Published: Jun 4, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded.

VendorProductVersions

HackerOne

Morris.js node module

affected
<=0.5.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now