Description
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.
References
https://github.com/jgraph/drawio/commit/ea012baba6fb2e903797fa6306833ca4f31ab361
PatchThird Party Advisory
https://huntr.dev/bounties/125791b6-3a68-4235-8866-6bc3a52332ba
ExploitPatchThird Party Advisory
https://github.com/jgraph/drawio/commit/ea012baba6fb2e903797fa6306833ca4f31ab361
PatchThird Party Advisory
https://huntr.dev/bounties/125791b6-3a68-4235-8866-6bc3a52332ba
ExploitPatchThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-09-16T09:15:12.107Z
3 years agoLast modified
2024-11-21T06:19:05.290Z
1 year ago