Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Wofwca

#46907of 53,624
5.4Total CVSS
Vulnerabilities · 1
PT-2022-17607
5.4
2022-12-21
Smoothie · Smoothie · CVE-2022-25929
**Name of the Vulnerable Software and Affected Versions** smoothie versions 1.31.0 through 1.36.1 **Description** The issue arises from improper user input sanitization in `strokeStyle` and `tooltipLabel` properties, leading to Cross-site Scripting (XSS). This can be exploited when a user has control over these properties. **Recommendations** For smoothie versions 1.31.0 through 1.36.1, consider disabling the use of `strokeStyle` and `tooltipLabel` properties until a patch is available to prevent potential XSS attacks. Restrict access to these properties to minimize the risk of exploitation.