Junglewise Threat Intelligence

CVE-2020-15092: Knight Lab TimelineJS3 stored XSS in data rendering

CVE-2020-15092 · Severity: low · CVSS 3.1 · Published 2020-07-09

Vendors: npm.

Executive brief

Knight Lab TimelineJS3 is a popular tool used by newsrooms and storytellers to create interactive timelines from data sources like Google Sheets. A security flaw allowed individuals with write access to the timeline's data source to insert malicious code that would execute in the browsers of people viewing the timeline. This could lead to unauthorized actions being performed on behalf of viewers or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in TimelineJS3 before version 3.7.0 due to improper neutralization of input during web page generation (CWE-79). The application fails to sanitize HTML markup in several data fields when rendering content from Google Sheets or JSON configuration files. An attacker with write access to the underlying data source—either through compromised credentials, malicious internal access, or insecure 'public edit' permissions—can inject malicious scripts. These scripts execute when a victim views the embedded timeline. The vulnerability is resolved in version 3.7.0 by implementing a sanitization process that strips dangerous tags while allowing safe styling markup.

Affected products

  • Knight Lab TimelineJS3 < 3.7.0
  • Knight Lab Knight Lab TimelineJS WordPress plugin < 3.7.0.0

Timeline

  • 2020-07-09: disclosed
  • 2020-07-09: patched: Version 3.7.0 released
  • 2020-07-09: advisory

References