cve/2022/CVE-2022-25929.md
2024-06-18 02:51:15 +02:00

916 B

CVE-2022-25929

Description

The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.

POC

Reference

Github

No PoCs found on GitHub currently.