CVE-2019-13127 Information
Feb 14, 2021
cve
Description
An issue was discovered in mxGraph through 4.0.0 related to the \draw.io Diagrams\ plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://github.com/jgraph/mxgraph/commit/76e8e2809b622659a9c5ffdc4f19922b7a68cfa3 https://marketplace.atlassian.com/apps/1210933/draw-io-diagrams-for-confluence/version-history https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-032.txt
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: