Vulnerabilities
Vulnerable Software
Jgraph:  >> Mxgraph  >> 1.13.0.14  Security Vulnerabilities
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-07-01
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
CVSS Score
9.8
EPSS Score
0.002
Published
2018-02-24


Contact Us

Shodan ® - All rights reserved