CVE-2020-28487
Published
CVSS v3
6.8
MEDIUM
CVSS v2
6
MEDIUM
Affected
1
PROJECT
Description
This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.
📅 Create a fully customizable, interactive timelines and 2d-graphs with items and ranges.