Vulnerabilities (CVE)

Filtered by vendor Northwestern
Filtered by product Timelinejs
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-15092 1 Northwestern 1 Timelinejs 2024-11-21 3.5 LOW 7.2 HIGH
In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON configuration file. Most TimelineJS users configure their timeline with a Google Sheets document. Those users are exposed to this vulnerability if they grant write access to the document to a malicious inside attacker, if the ...

Show More