Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2022-40440
Disclosure Date: October 12, 2022 (last updated February 24, 2025)
mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
0
Attacker Value
Unknown
CVE-2019-13127
Disclosure Date: July 01, 2019 (last updated November 27, 2024)
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.
0
Attacker Value
Unknown
CVE-2017-18197
Disclosure Date: February 24, 2018 (last updated November 26, 2024)
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
0