We found results for “”
WS-2020-0121
Good to know:
Date: June 9, 2020
highcharts before 8.1.1 is vulnerable to Cross-Site Scripting. An attacker can exacute arbitrary code from chart configuration string.
Language: JS
Severity Score
Severity Score
Top Fix
Upgrade Version
Upgrade to version geek1992/tp5_rbac - 1.0.0;geek1992/tp5_rbac - no_fix;codeblanche/depend - 1.1.2;codeblanche/depend - no_fix;codeblanche/depend - 1.0.0rc1;grumpydictator/firefly-iii - dev-dependabot/composer/develop/doctrine/dbal-3.1.1;grumpydictator/firefly-iii - dev-dependabot/composer/develop/doctrine/dbal-3.1.4;grumpydictator/firefly-iii - dev-dependabot/composer/composer-a1e7ad0bd3;grumpydictator/firefly-iii - dev-dependabot/composer/develop/laravel/sanctum-3.0.1;grumpydictator/firefly-iii - dev-dependabot/npm_and_yarn/develop/date-fns-3.0.6;forkcms/forkcms - dev-dependabot/composer/squizlabs/php_codesniffer-3.8.0;forkcms/forkcms - dev-dependabot/composer/ramsey/uuid-3.9.4;forkcms/forkcms - dev-dependabot/composer/squizlabs/php_codesniffer-3.8.1;forkcms/forkcms - dev-dependabot/composer/squizlabs/php_codesniffer-3.9.0;forkcms/forkcms - dev-dependabot/composer/squizlabs/php_codesniffer-3.6.2;forkcms/forkcms - dev-dependabot/composer/squizlabs/php_codesniffer-3.7.1;forkcms/forkcms - dev-dependabot/composer/squizlabs/php_codesniffer-3.7.0;forkcms/forkcms - dev-dependabot/composer/ramsey/uuid-3.9.6;forkcms/forkcms - dev-dependabot/composer/squizlabs/php_codesniffer-3.6.0;forkcms/forkcms - dev-dependabot/composer/squizlabs/php_codesniffer-3.6.1;symfomany/laravelcinema - no_fix;eher/phpunit - no_fix;eher/phpunit - 1.0;RenderHighCharts.Render - no_fix;jadu/pulsar - dev-dependabot/npm_and_yarn/tar-2.2.2;jadu/pulsar - dev-dependabot/npm_and_yarn/docs/eta-and-docusaurus/core-and-docusaurus/preset-classic-2.0.0;jadu/pulsar - 1.0.19;jadu/pulsar - dev-dependabot/npm_and_yarn/hosted-git-info-2.8.9;jadu/pulsar - dev-twig-2.1;jadu/pulsar - dev-dependabot/npm_and_yarn/minimatch-and-mocha-3.1.2;jadu/pulsar - dev-poc/twig3;itboye/sunsun_tcp - v2.0;abraxas81/charts - dev-analysis-8PoaGK;abraxas81/charts - dev-analysis-XNL37r;abraxas81/charts - 5.0.1;abraxas81/charts - dev-analysis-q1ZyJN;abraxas81/charts - dev-analysis-86GJ4W;abraxas81/charts - 1.8.1;abraxas81/charts - dev-add-code-of-conduct-1;abraxas81/charts - dev-analysis-XlmdgV;abraxas81/charts - dev-analysis-zdnnkj;abraxas81/charts - 3.0;abraxas81/charts - no_fix;abraxas81/charts - dev-analysis-8brReQ;abraxas81/charts - dev-analysis-qom0Bb;abraxas81/charts - dev-analysis-zDKmEJ;abraxas81/charts - dev-scrutinizer-patch-2;consoletvss/chartss - dev-analysis-q1ZyJN;consoletvss/chartss - dev-analysis-8brReQ;consoletvss/chartss - dev-analysis-zdnnkj;consoletvss/chartss - dev-analysis-XNL37r;consoletvss/chartss - dev-analysis-86GJ4W;consoletvss/chartss - dev-analysis-XlmdgV;consoletvss/chartss - dev-analysis-qom0Bb;consoletvss/chartss - no_fix;consoletvss/chartss - dev-scrutinizer-patch-2;consoletvss/chartss - 3.0;consoletvss/chartss - dev-analysis-8PoaGK;adkgamers/bfadmincp - v2.0.0-rc.1;adkgamers/bfadmincp - no_fix;adkgamers/bfadmincp - dev-dependabot/composer/guzzlehttp/guzzle-6.5.6;letyii/yii2-chart - no_fix;kazist/kazist - 1.0.1;kazist/kazist - 1.0.11;kazist/kazist - 1.0.15;kazist/kazist - no_fix;tiderjian/think-core - v7.0.1;tiderjian/think-core - v12.0.5;tiderjian/think-core - v11.13.10;tiderjian/think-core - v11.34.3;tiderjian/think-core - v12.0.8;tiderjian/think-core - v3.1.2;tiderjian/think-core - dev-dependabot/npm_and_yarn/asset/libs/label-select/ssri-6.0.2;tiderjian/think-core - v2.3.5;tiderjian/think-core - v11.x-dev;tiderjian/think-core - v11.33.4;tiderjian/think-core - v13.0.0;tiderjian/think-core - v11.30.0;tiderjian/think-core - v7.2.0;tiderjian/think-core - v8.0.4;tiderjian/think-core - v12.0.0;tiderjian/think-core - v8.0.1;tiderjian/think-core - v11.34.7;tiderjian/think-core - v11.13.6;tiderjian/think-core - v11.19.10;tiderjian/think-core - v11.30.4;tiderjian/think-core - dev-dependabot/npm_and_yarn/asset/libs/label-select/postcss-7.0.36;tiderjian/think-core - dev-dependabot/npm_and_yarn/asset/libs/label-select/ajv-6.12.6;tiderjian/think-core - dev-dependabot/npm_and_yarn/asset/libs/label-select/tar-4.4.19;tiderjian/think-core - v11.34.0;tiderjian/think-core - v11.13.4;opencontent/ocsensor-ls - dev-chart2data;opencontent/ocsensor-ls - dev-bootstrapitalia;opencontent/ocsensor-ls - dev-user-settings;opencontent/ocsensor-ls - 5.6.0;opencontent/ocsensor-ls - dev-custom-policies-filter;opencontent/ocsensor-ls - dev-reports;opencontent/ocsensor-ls - 1.0;opencontent/ocsensor-ls - dev-fix-perfomance;opencontent/ocsensor-ls - dev-statistic-collector;opencontent/ocsensor-ls - dev-override-notification-type-target;opencontent/ocsensor-ls - dev-faq-predictor;opencontent/ocsensor-ls - dev-master;opencontent/ocsensor-ls - dev-criticals;opencontent/ocsensor-ls - dev-refactor-refresh;opencontent/ocsensor-ls - dev-inbox;limesurvey/limesurvey - dev-dev-feature-api-add-quota-completeCount;limesurvey/limesurvey - dev-test-log-checks;limesurvey/limesurvey - dev-snyk-upgrade-3ddd041b50fb018d81e7711467a35e76;limesurvey/limesurvey - dev-travis-postgre;limesurvey/limesurvey - dev-fieldmap;limesurvey/limesurvey - 3.0.0+171222;limesurvey/limesurvey - dev-scrutinizer-patch-1;opencontent/openpa_agenda-ls - dev-temp_luca;opencontent/openpa_agenda-ls - no_fix;opencontent/openpa_agenda-ls - 1.28.1;opencontent/openpa_agenda-ls - 1.26.0;edguy/admin_panel - 1.0;edguy/admin_panel - no_fix;mwardi/highcharts-bundle - v1.5;mwardi/highcharts-bundle - v1.7-alpha;mwardi/highcharts-bundle - v1.1;mwardi/highcharts-bundle - v1.3;mwardi/highcharts-bundle - no_fix;cheukpang/think-worker - v3.1.1;scylabs/neptune-bundle - no_fix;scylabs/neptune-bundle - v1.0.11;scylabs/neptune-bundle - v1.1.9;scylabs/neptune-bundle - v1.0.9;scylabs/neptune-bundle - v1.0.4;scylabs/neptune-bundle - v1.1.10;scylabs/neptune-bundle - v1.2.0;scylabs/neptune-bundle - v1.0.7;scylabs/neptune-bundle - v1.0.13;scylabs/neptune-bundle - v1.1.8;scylabs/neptune-bundle - v1.0.12;scylabs/neptune-bundle - v1.0.3;scylabs/neptune-bundle - 1.2.13;scylabs/neptune-bundle - v1.0.1;scylabs/neptune-bundle - v1.0.6;scylabs/neptune-bundle - v1.1.7;scylabs/neptune-bundle - v1.1.12;scylabs/neptune-bundle - v1.1.5;scylabs/neptune-bundle - v1.1.6;scylabs/neptune-bundle - v1.0.5;scylabs/neptune-bundle - 1.3.1;scylabs/neptune-bundle - v1.4.13;scylabs/neptune-bundle - v1.0.0;scylabs/neptune-bundle - v1.0.2;scylabs/neptune-bundle - v1.0.8;scylabs/neptune-bundle - v1.1.11;scylabs/neptune-bundle - v1.0.10;winmillwill/settings_compile - no_fix;winmillwill/settings_compile - 1.0.4;ics/socialnetwork-bundle - 1.0.15;ics/socialnetwork-bundle - 0.0.1;authorizit/authorizit - v1.0.0;nahapa/module-user - v0.0.1;jdlabails/php-project-analyzer-bundle - no_fix;jdlabails/php-project-analyzer-bundle - 1.5.0;trungtnm/backend - 1.1;trungtnm/backend - list;madpeterz/yetonemorephpframework - 3.0.8;madpeterz/yetonemorephpframework - 2.0.2;madpeterz/yetonemorephpframework - 4.2.1;madpeterz/yetonemorephpframework - 4.1.1;vncore/core - no_fix;kohkimakimoto/earray - v2.0.0;okaycms/okaycms - dev-feature/fix_breadcrumbs_for_login_register_pass_remind;okaycms/okaycms - dev-revert-41-feature/add_delimeter_features_1c;okaycms/okaycms - dev-feature/refactor_chpu_filter;okaycms/okaycms - dev-master;okaycms/okaycms - dev-bugfix/xml_feed_helper_visible_features;okaycms/okaycms - dev-feature/test_pr;okaycms/okaycms - dev-bugfix/fix_rozetka_feed;okaycms/okaycms - 4.3.0;okaycms/okaycms - 4.0.1;okaycms/okaycms - dev-feature/console_application;okaycms/okaycms - no_fix;okaycms/okaycms - dev-feature/front_fixes;n7consulting/jeyser-crm - no_fix;n7consulting/jeyser-crm - v.1.0.1;n7consulting/jeyser-crm - 2.0.0-beta.1;n7consulting/jeyser-crm - v2.8.0;i9code/laravelmetronic3 - no_fix;laravel2016/charts - 1.4;laravel2016/charts - 3.0;laravel2016/charts - 1.8.1;weiphpdev/weiphp5 - no_fix;micheldamasceno/mercadolibre - no_fix;asherkin/throttle - v4.x-dev;Apace - 1.0.2;Apace - no_fix;rsoftech/role - v1.0.0;macweb/meli-php-sdk - dev-meli-v3.0.0;macweb/meli-php-sdk - dev-test-bugs-resolved;boost - 1.73.0;boost - 1.71.0;boost - 1.75.0;yuanling/workerman - 3.x-dev;truckee/projectmana - 3.0;truckee/projectmana - 4.0.0;truckee/projectmana - no_fix;zerkalica/phpunit - no_fix;zerkalica/phpunit - dev-master;benborla/xampp - no_fix;daoke5/yii-plus - no_fix;vinala/kernel - dev-database-slowness-repairing;hahadu/php-device - v0.1.0;ogsteam/ogspy - no_fix;ogsteam/ogspy - dev-UpdateJSLibs2;ogsteam/ogspy - dev-OGSpy_3.4;ogsteam/ogspy - 3.3.6;ogsteam/ogspy - 3.3.7-alpha5;ogsteam/ogspy - 3.1.1;magirc/magirc - v0.9.0;alternatex/store - 1.0.1;alternatex/store - no_fix;vw/framework - v1.0.0;vw/framework - v1.2.0;vw/framework - v1.0.8;kodicms/cms - no_fix;eng-mmarouf/metronic - no_fix;thomasvargiu/laminas-twb-bundle - dev-fix/zf2;thomasvargiu/laminas-twb-bundle - 2.3.0;jakabj16/yii2-highcharts-widget - 1.0.0;da/stat-bundle - no_fix;civicrm/civicrm-packages - 4.6.0;civicrm/civicrm-packages - 4.4.1;splicephp/app - 3.0.0-RC1;khotim/yii2-highcharts - no_fix;promet/settings_compile - 1.0.4;promet/settings_compile - no_fix;mango/cflash - no_fix;mango/cflash - v1.0;gufy/assets-services - v1.1.3;matomo/matomo - dev-dependabot-github_actions-ncipollo-release-action-1.14.0;matomo/matomo - 2.0.4-b8;matomo/matomo - dev-2.x-dev;matomo/matomo - 2.0.4-b10;erik/laralum - 1.0;erik/laralum - no_fix;zafranf/zetthcore - v0.4.35;zafranf/zetthcore - v0.4.39;zafranf/zetthcore - v0.5.0;zafranf/zetthcore - v0.1.0;zafranf/zetthcore - no_fix;cgbin/cgblog - no_fix;facuramirez/mercado-libre-php-sdk - no_fix;icedevelop/layout-bundle - no_fix;maurolacerda-tech/ml-framework - no_fix;i9code/laravelmetronic - no_fix;diablomedia/laminas-twb-bundle - dev-dependabot/composer/phpstan/phpstan-1.11.0;diablomedia/laminas-twb-bundle - 2.3.0;moszkva/angie - no_fix;trash-panda/m2-opcache-monitor - no_fix;consynki/yii2-highcharts - no_fix;pasoka/framework - no_fix;netbrain/highcharts-js - no_fix;shuwon/admin - 1.0.0;i9code/laravelmetronic2 - no_fix;moszkva/cgraph - no_fix;moszkva/cgraph - v.2.2;arnulfosolis/qcharts - no_fix;Kalitte.Dashboard.SampleApp - no_fix;brebvix/workerman - v3.1.1;miloschuman/yii-highcharts - no_fix;miloschuman/yii-highcharts - v0.4;arnapou/gw2tools - 1.x-dev;ch4o5/x-tek_cmf - no_fix;lobostome/furry-bear - dev-master;lobostome/furry-bear - 0.7.2;aerni/translator - dev-dependabot/npm_and_yarn/minimist-1.2.6;csbill/csbill - 0.7.0;elijaa/phpmemcacheadmin - 1.0.0;DotNet.Highcharts - 2.0.0;DotNet.Highcharts - no_fix;sizannia/data-analytics-bundle - no_fix;tiderjian/qscmf - v2.0.0;tiderjian/qscmf - dev-rebuild1;madephp/framework - no_fix;youshido/admin - no_fix;youshido/admin - 0.0.1;neilime/zf2-mobile-detect - 2.0.0;piwik/piwik - dev-2.x-dev;piwik/piwik - dev-dependabot-github_actions-ncipollo-release-action-1.14.0;piwik/piwik - 2.0.4-b8;piwik/piwik - 2.0.4-b10;alejoasotelo/mercadolibre-php-sdk - no_fix;francodacosta/phmagick - no_fix;melibox/mercadolibre-php-sdk - no_fix;melibox/mercadolibre-php-sdk - 1.0.3;imperiumclan/media-bundle - no_fix;tokalink/panel - no_fix;agapito78/php-sdk - no_fix;loopeer/quickcms - no_fix;KradPanel - no_fix;aw/formfields - no_fix;XPanel - no_fix;hatframework/hat-resource-charts - no_fix;hatframework/hat-resource-charts - v0.3.2;S-money.Api.Wrapper - 1.0.2.3-alpha;etdsolutions/highcharts - no_fix;landrok/webstatus - no_fix;jianzi/runcms - no_fix;mrchen/thriftrpc - no_fix;highcharts.js - 7.1.2;tellaw/sunshine-admin-bundle - v0.9.23;tellaw/sunshine-admin-bundle - v0.9.10;tellaw/sunshine-admin-bundle - v0.9.21;highcharts - 8.1.1;highcharts - 7.2.2;hamichen/zf2-twb-bundle - 2.0;zf2-boiler-app/app-db - no_fix;shavy/qcache - v1.0.2;clevertech/yii-booster - 1.0.5;clevertech/yii-booster - v2.0.0;hai121341169/hai-thrift-rpc - no_fix;junqing124/dcrphp - no_fix;miaoxing/stat - no_fix;observableworker/observableworker - v3.1.1;2amigos/yii2-highcharts-widget - 1.0.0;zyblog/yii2-bjui - no_fix;dyhhub/p - no_fix;tfarias/instalador-tfarias - no_fix;tfarias/instalador-tfarias - dev-master;kisma/kisma - dev-master;kfilin/ksutils - no_fix;kfilin/ksutils - v1.0;shiyun/php-worker - no_fix;marcelojeff/php-sdk - no_fix;stiki-asset/sisfo - no_fix;hilioski/charts - no_fix;hilioski/charts - 1.8.1;neilime/zf2-browscap - 1.1;remp/crm-skeleton - no_fix;remp/crm-skeleton - 1.2.0;remp/crm-skeleton - 1.0.0;remp/crm-skeleton - 1.6.0;remp/crm-skeleton - 1.4.0;grimmlink/highcharts - v4.2.5;novum/innovation-app-core - dev-temp-commit;shavy/s-array - v1.0.3;meshood/cflash - no_fix;meshood/cflash - v0.1;topazcms/core - no_fix;raoul2000/yii-simple-workflow - no_fix;flash20/yii2-adminh-asset - no_fix;wp-cloud/phpmemcacheadmin - 1.0.0;miloschuman/yii2-highcharts-widget - v6.0;kiyora/dashboard-generator - no_fix;dreamfactory/service-oauth - dev-feature/refactor;dreamfactory/service-oauth - 0.1.2;whoosh/elaadmin - no_fix;crisnao2/meli - no_fix;pimientadigital/yii-booster - v2.0.0;pimientadigital/yii-booster - 1.0.5;r-highcharter - 0.5.0;imagecms/imagecms - no_fix;imagecms/imagecms - dev-phpunit;mikepsinn/php-highcharts-exporter - 1.0.3;zyuyou/workerman - v3.1.1;dcrphp/core - 1.0.7-alpha5;s-cart/s-cart - v6.5.0-beta;s-cart/s-cart - v1.0-beta;s-cart/s-cart - v6.8.3;s-cart/s-cart - v6.7.4;s-cart/s-cart - no_fix;zf2-boiler-app/app-logger - no_fix;michalwolinski/wbiztool-laravel - dev-dependabot/composer/symfony/http-foundation-4.4.7;damnpoet/yiicart - no_fix;workerman/statistics - no_fix;arionum/pool - no_fix;webscale/webscale - no_fix;dreamfactory/oasys - dev-feature/refactor;dreamfactory/oasys - 0.1.2;drarko/meli-php-sdk - no_fix;tomzx/anki-charts - no_fix;sonsuzdongu/haller.php - no_fix;yikesinc/yikes-inc-easy-mailchimp-extender - 5.1.0.1;bioconductor-fastqcleaner - no_fix;walkor/workerman - 3.x-dev;mothership-ec/cog-mothership-file-manager - dev-develop;bismark - 0.20.0;DCoolWeb.Web.SW - no_fix;maxiter/maxiter - no_fix;abouttheweb/zf2-twb-bundle - 2.3.0;mrs/sgv - no_fix;mrs/sgv - 2.9.8;davehensley/highcharts - highstock-v1.0.1;livestreet/plugin-admin - no_fix;sergeyugai/badpack - dev-dependabot/composer/symfony/http-kernel-5.4.20;cyzonetech/workerman - 3.x-dev;azuracast/azuracast - 0.9.5.1;reedboat/yiiwheels - no_fix;reedboat/yiiwheels - 1.0.0;rogeriopradoj/box-php52-codeigniter-skeleton - no_fix;nosh2/nosh2 - dev-dependabot/composer/guzzlehttp/guzzle-7.4.3;nosh2/nosh2 - dev-dependabot/npm_and_yarn/ini-1.3.8;nosh2/nosh2 - no_fix;arielcr/tipocambio-bccr - no_fix;artic - 1.2.1;lizetheb1920/high-chart - no_fix;hinkelmann/friga - no_fix;brnskn/charts - 3.0;friendsofvictoire/statistic-widget - no_fix;2amigos/yiiwheels - 1.0.0;2amigos/yiiwheels - 2.0.0;2amigos/yiiwheels - 1.0.7-beta;2amigos/yiiwheels - no_fix;kingkernel/marrento - no_fix;kingkernel/marrento - stable;edtau-table/ctable - no_fix;igeekspace/twothink - no_fix;galvani/cn-group-test - no_fix;prog/logger - no_fix;42-9/neptune-bundle-menu - no_fix;dlin/saasu - v1.0.0;multiqc - 1.22;zhangyanxin1314/quickphp - no_fix;pbk83/csimpletable - v1.0;truesocialmetrics/zf2-twb-bundle - 2.3.0;xdevelopers.web - no_fix;hieupham0206/cloudteam-metronic - no_fix;xtgxiso/webworker - 0.1.3;kmaking/admin-template - no_fix;kmaking/admin-template - v1.0.4;kmaking/admin-template - v1.0.1;csoftech/customer - no_fix;bjam-native - 1.73.0;bjam-native - 1.63.0;neilime/zf2-assets-bundle - 2.1;soq/linkmunch - no_fix;zymawy/ironside-core - dev-utils;pan/quick-profiler - no_fix;webeweb/highcharts-bundle - v1.0;usoftech/user - no_fix;carlescliment/query-builder - v1.0.1;carlescliment/query-builder - no_fix;scelusswe/escaper - no_fix;zf2-boiler-app/app-access-control - no_fix;gosyl/common-bundle - 1.0;cornernote/highcharts-assets - no_fix;neilime/zf2-tree-layout-stack - 1.0;mladindima/charts - 3.0;drupalchamp/crypto_distribution - no_fix;sunjiaqiang/codeigniter-integration - no_fix;tristanbes/elophant-bundle - no_fix;whole/core - no_fix;i9code/metronic - no_fix;maioradv/admin2-cdn - no_fix;yinhe/yincart - no_fix;kazist/assets - 1.0.0;solidinvoice/solidinvoice - dev-dependabot/npm_and_yarn/moment-timezone-0.5.37;solidinvoice/solidinvoice - 0.7.0;getdevflow/cmf - no_fix;jonatasavila-mercadolibre/php-sdk - 1.0.0;murrion/bullethq - no_fix;opencontent/occhart-ls - 2.0.0;kevintcoughlin/citibike - no_fix;laraflat/laraflat - no_fix;angular-highcharts - no_fix;jlaso/tradukoj - 1.1;skeeks/yii2-widget-highcharts - 1.0.0;incodiy/codiy - no_fix;ceman/mercadolibre-php-sdk - no_fix;husseinsayed/charts - no_fix;lugosium/lugosiumovhvpsmonitorbundle - no_fix;joegreen0991/fieldset - no_fix;gp247/core - no_fix;fedorov-aleksey/yii2-package-theme-absolute-admin - v1.0.2;fedorov-aleksey/yii2-package-theme-absolute-admin - no_fix;ugly/form - no_fix;scalejs.highcharts - no_fix;vaisakhshiva/php-code-coverage - 1.2.14;simonjodet/gumdrop - 1.2.0;HighCharts - no_fix;codefyphp/skeleton - v2.0.0;coffee/code-framework - 1.1;xristmas365/basic - no_fix;zf2-boiler-app/app-messenger - no_fix;ifcnv - no_fix;ivanbay/rosecomarketingventure - no_fix;developerhub/php-testcase - no_fix;remiheens/dbbalancer - no_fix;suitmedia/suitcoda - 1.0.0-beta0;tungphan/yii-demo - no_fix;fastd/asset-bundle - no_fix;csoftech/cms - no_fix;mshule/laravel-pipes - v1.2;snide/travinizer-bundle - 1.1.0;org.webjars:highcharts:8.2.2;org.webjars:highcharts:7.2.1;org.webjars.bower:github-com-highcharts-highcharts:no_fix;org.webjars.npm:highcharts:no_fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


