AIKIDO-2024-10155

echarts is vulnerable to Cross-site Scripting

60

Medium

echarts

AIKIDO-2024-10155: echarts is vulnerable to Cross-site Scripting in versions 2.2.8 - 5.5.0.

Cross-site Scripting
Vuln in 2.2.8 - 5.5.0
Fixed in 5.5.1
No CVE available
TL;DR

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the tooltip of charts.

Who does this affect?

You're affected if you are using a vulnerable version of the package, and pass user input to the chart's tooltip (directly or indirectly, such as via a different component).

How can it be fixed?

Upgrade echarts to a patch version.

Are you
to these issues?
Connect your GitHub, GitLab, Bitbucket or Azure DevOps account to start scanning your repos for free.
Start For Free
Your data won't be shared · Read-only access
Logo
© 2024 Aikido Security BV | BE0792914919
🇪🇺 Grauwpoort 1, 9000 Ghent, Belgium
🇺🇸 95 Third St, 2nd Fl, San Francisco, CA 94103, US