CVE-2019-13127
Last modified
CVE-2019-13127 is a vulnerability of currently unknown severity. An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Draw | Draw.Io Diagrams | < 8.3.14 |
| Jgraph | Mxgraph | <= 4.0.0 |
References
- https://github.com/jgraph/mxgraph/commit/76e8e2809b622659a9c5ffdc4f19922b7a68cfa3Patch, Third Party Advisory
- https://marketplace.atlassian.com/apps/1210933/draw-io-diagrams-for-confluence/version-historyRelease Notes, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-032.txtExploit, Third Party Advisory
- https://github.com/jgraph/mxgraph/commit/76e8e2809b622659a9c5ffdc4f19922b7a68cfa3Patch, Third Party Advisory
- https://marketplace.atlassian.com/apps/1210933/draw-io-diagrams-for-confluence/version-historyRelease Notes, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-032.txtExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13127?
How severe is CVE-2019-13127?
How do I fix CVE-2019-13127?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-13121An issue was discovered in GitLab Enterprise Edition 10.6 th…7.5
- CVE-2019-13122A Cross Site Scripting (XSS) vulnerability exists in the tem…
- CVE-2019-13123Foxit Reader 9.6.0.25114 and earlier has two unique Recursiv…7.5
- CVE-2019-13124Foxit Reader 9.6.0.25114 and earlier has two unique Recursiv…7.5
- CVE-2019-13125HaboMalHunter through 2.0.0.3 in Tencent Habo allows attacke…
- CVE-2019-13126An integer overflow in NATS Server before 2.0.2 allows a rem…7.5
- CVE-2019-13128An issue was discovered on D-Link DIR-823G devices with firm…
- CVE-2019-13129On the Motorola router CX2L MWR04L 1.01, there is a stack co…
- CVE-2019-1313An information disclosure vulnerability exists in Microsoft …6.5
- CVE-2019-13131Super Micro SuperDoctor 5, when restrictions are not impleme…
- CVE-2019-13132In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x…9.8
- CVE-2019-13133ImageMagick before 7.0.8-50 has a memory leak vulnerability …5.5
Are you affected by CVE-2019-13127?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
