CVE-2017-16022
MEDIUMmorris.js < 0.5.0 - Stored Cross-Site Scripting in SVG Graph Hover Labels
Title source: llmDescription
Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://nodesecurity.io/advisories/307
Third Party Advisory x_refsource_misc
https://github.com/morrisjs/morris.js/pull/464
Scores
CVSS v3
6.1
EPSS
0.0091
EPSS Percentile
56.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
morris.js_project/morris.js
< 0.5.0
npm/morris.js
npm
Published
Jun 04, 2018
Tracked Since
Feb 18, 2026