CVE-2017-16022

MEDIUM

morris.js < 0.5.0 - Stored Cross-Site Scripting in SVG Graph Hover Labels

Title source: llm
STIX 2.1

Description

Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://nodesecurity.io/advisories/307
Third Party Advisory x_refsource_misc
https://github.com/morrisjs/morris.js/pull/464

Scores

CVSS v3 6.1
EPSS 0.0091
EPSS Percentile 56.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
morris.js_project/morris.js < 0.5.0
npm/morris.js npm
Published Jun 04, 2018
Tracked Since Feb 18, 2026