MEDIUM 6.1 npm
Cross Site Scripting (XSS) in plotly.js
GHSA-2fqv-h3r5-m4vf · CVE-2017-1000006
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Affected versions of plotly.js are vulnerable to cross-site scripting if an attacker can convince a user to visit a malicious plot on a site using this package.
Recommendation
Update to 1.16.0 or later.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2017-1000006
- WEB https://acloudtree.com/2016-08-09-how-i-hacked-plotly-by-exploiting-a-svg-vulnerability-in-plotlyjs
- ADVISORY https://github.com/advisories/GHSA-2fqv-h3r5-m4vf
- WEB https://www.npmjs.com/advisories/145
- WEB http://help.plot.ly/security-advisories/2016-08-08-plotlyjs-xss-advisory
Ready to move
Start Securing
Free, no credit card | First findings in minutes