Executive brief
ApexCharts is a popular JavaScript charting library used to create interactive data visualizations in web applications. The library failed to properly sanitize user-supplied content in chart legend and tooltip fields, allowing attackers to inject malicious JavaScript code that executes in users' browsers when viewing affected charts. An exploit could lead to session hijacking, credential theft, or other client-side attacks against application users.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw caused by insufficient input sanitization in ApexCharts' rendering of chart legend and label fields. Specifically, the `name` and `label` fields were not properly escaped before being rendered in tooltips and chart legends, allowing injection of HTML and JavaScript payloads (e.g., `<img src=x onerror=alert(1)>`). The attack requires no authentication and is triggered by rendering a malicious chart configuration in a web browser, making the network vector applicable. The vulnerability was patched in version 3.24.0 by implementing proper sanitization of these fields before rendering.
Affected products
- ApexCharts ApexCharts before 3.24.0
Timeline
- 2021-02-11: disclosed
- 2021-02-10: patched: Fix merged in PR #2158