#VU64171 Code Injection in draw.io - CVE-2022-2014
Published: June 10, 2022 / Updated: June 10, 2022
draw.io
JGraph
Description
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation in the nodeName and nodeValue parameters in the tooltips function. A remote attacker can trick the victim to visit a specially crafted link and execute arbitrary JavaScript code in victim's browser in the security context of the website.