Junglewise Threat Intelligence

CVE-2019-13127: mxGraph cross-site scripting in color field

CVE-2019-13127 · Severity: low · CVSS 3 · Published 2022-05-24

Technologies: mxgraph (npm). Vendors: JGraph, npm.

Executive brief

mxGraph is a JavaScript library used to create and edit diagrams, including integration with Confluence via the draw.io Diagrams plugin. A flaw in the color field input allows attackers to inject JavaScript code that executes in visitors' browsers, potentially enabling session hijacking, credential theft, or malicious command execution within Confluence.

Technical details

mxGraph through version 4.0.0 contains a cross-site scripting (CWE-79) vulnerability in the color field input handler. The vulnerability exists because user-supplied color values are not properly sanitized before being rendered as HTML/CSS, allowing an attacker to inject arbitrary JavaScript code by crafting a malicious color string (e.g., "onMouseOver=alert(1) a="). The attack requires user interaction (hovering over the diagram element) and affects the Confluence draw.io Diagrams plugin and other products integrating mxGraph. An attacker can execute arbitrary JavaScript in the victim's browser session to perform actions as the victim. The fix was implemented in version 4.0.1 by adding input validation for color codes.

Affected products

  • JGraph mxGraph through 4.0.0

Timeline

  • 2019-07-01: disclosed
  • 2019: patched: Version 4.0.1 released with input validation for color codes
  • 2022-05-24: advisory: GHSA-xm59-jvxm-cp3v published

References

Related threats