CVE-2020-16254

Published about 2 months ago
Category: Code Injection
Source: GitHub
Severity: Moderate

Vulnerability in chartkick

Chartkick is vulnerable to CSS injection if user input is passed to the width or height option.

<%= line_chart data, width: params[:width], height: params[:height] %>

An attacker can set additional CSS properties, like:

<%= line_chart data, width: “100%; background-image: url(‘http://example.com/image.png’)” %>

CVSS Metrics
Access Vector Access Complexity Authentication Confidentiality Impact Integrity Impact Availability Impact
n/a n/a n/a n/a n/a n/a
Patched Versions

>= 3.4.0

Unaffected Versions

n/a

References

n/a