- CVE ID
- CVE-2020-28487
- CVE Description
- This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.
- Published
- Jan 25, 2021
- CVSS Score & Severity
6.0Medium
- CVSS Vector
- AV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS Score
- 0.517%
- KEV Status
Not in KEV Catalog: No known exploits
- Source
- National Vulnerability Database