mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-29 16:29:28 +02:00
830 B
830 B
CVE-2020-28487
Description
This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.
POC
Reference
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBVISJS-1063502
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1063501
- https://snyk.io/vuln/SNYK-JS-VISTIMELINE-1063500
Github
No PoCs found on GitHub currently.