GHSA-fwx5-5fqj-jv98

    Dashboard / Vulnerabilities / GHSA-fwx5-5fqj-jv98

    GHSA-fwx5-5fqj-jv98

    Published: 9 Nov 2018Last Modified: 8 Nov 2023

    Summary: Cross-Site Scripting in morris.js

    Details: Affected versions of `morris.js` are vulnerable to cross-site scripting attacks in labels that appear when hovering over a particular point on a generated graph. The text content of these labels is not escaped, so if control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded. ## Recommendation A patch for this vulnerability was created in 2014, but has still not been published to npm. In order to mitigate this issue effectively, install the library from github via: ``` npm i morrisjs/morris.js -s ```

    Affected packages

    Package

    Name: morris.js

    Purl: pkg:npm/morris.js

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.5.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High