frappe-charts@1.5.2 vulnerabilities

https://frappe.github.io/charts

Direct Vulnerabilities

Known vulnerabilities in the frappe-charts package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Cross-site Scripting (XSS)

frappe-charts is a https://frappe.github.io/charts

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). An XSS vulnerability exists in src/js/utils/axis-chart-utils.js due to an incomplete fix for Cross-site Scripting (XSS) frappe-charts - 1.5.5 .

How to fix Cross-site Scripting (XSS)?

A fix was pushed into the master branch but not yet published.

*
  • M
Cross-site Scripting (XSS)

frappe-charts is a https://frappe.github.io/charts

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). It doesn't directly consume anything from the user, the attack vector for an XSS is quite a few layers deep.

PoC

'><img/&#09;&#10;&#11; src=~ onerror=~ alert('XSS')>

How to fix Cross-site Scripting (XSS)?

Upgrade frappe-charts to version 1.5.5 or higher.

<1.5.5