Cross-Site Scripting in highcharts
High severity
GitHub Reviewed
Published
Aug 25, 2020
to the GitHub Advisory Database
•
Updated Nov 10, 2023
Description
Reviewed
Aug 25, 2020
Published to the GitHub Advisory Database
Aug 25, 2020
Last updated
Nov 10, 2023
Versions of
highcharts
prior to 7.2.2 or 8.1.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitizehref
values and does not restrict URL schemes, allowing attackers to execute arbitrary JavaScript in a victim's browser if they click the link.References