{"id":"CVE-2019-13127","details":"An issue was discovered in mxGraph through 4.0.0, related to the \"draw.io Diagrams\" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.","aliases":["GHSA-xm59-jvxm-cp3v"],"modified":"2026-07-08T05:53:23.433559213Z","published":"2019-07-01T15:15:11.647Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"8.3.14"}],"source":"CPE_RANGE","vendor_product":"draw:draw.io_diagrams","cpes":["cpe:2.3:a:draw:draw.io_diagrams:*:*:*:*:*:confluence:*:*"]}]},"references":[{"type":"ADVISORY","url":"https://marketplace.atlassian.com/apps/1210933/draw-io-diagrams-for-confluence/version-history"},{"type":"FIX","url":"https://github.com/jgraph/mxgraph/commit/76e8e2809b622659a9c5ffdc4f19922b7a68cfa3"},{"type":"EVIDENCE","url":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-032.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jgraph/mxgraph","events":[{"introduced":"0"},{"last_affected":"33911ed7e055c17b74d0367f5f1f6c9ee4b4fd44"},{"fixed":"76e8e2809b622659a9c5ffdc4f19922b7a68cfa3"}],"database_specific":{"cpe":"cpe:2.3:a:jgraph:mxgraph:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"4.0.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v4.0.0","v3.9.12","v3.9.11","v3.9.10","v3.9.9","v3.9.8","v3.9.7","v3.9.6","v3.9.5","v3.9.4","v3.9.3","v3.9.2","v3.9.1","v3.9.0","v3.8.0","v3.7.6","v3.7.5","v3.7.4","v3.7.3","v3.7.2","v3.7.1","v3.7.0.1","v3.7.0.0","v3.6.0.0","v3.5.1.5","v3.5.1.4","v3.5.1.3","v3.5.1.2","v3.5.1.1","v3.5.1.0","v3.5.0.0","v3.4.1.3","v3.4.1.2","v3.4.1.1","v3.4.1.0","v3.4.0.3","v3.4.0.2","v3.4.0.1","v3.4.0.0","v3.3.1.1","v3.3.1.0","v3.3.0.1","v3.3.0.0","v3.2.0.0","v3.1.3.0","v3.1.2.2","v3.1.2.1","v3.1.2.0","v3.1.1.1","v3.1.1.0","v3.1.0.1","v3.1.0.0","v3.0.1.1","v3.0.1.0","v3.0.0.0","v2.9.0.1","v2.9.0.0","v2.8.2.0","v2.8.1.0","v2.8.0.0","v2.7.0.0","v2.6.0.0","v2.5.1.0","v2.5.0.3","v2.5.0.2","v2.5.0.1","v2.5.0.0","v2.4.1.0","v2.4.0.4","v2.4.0.3","v2.4.0.2","v2.4.0.1","v2.4.0.0","v2.3.0.5","v2.3.0.4","v2.3.0.3","v2.3.0.2","v2.3.0.1","v2.3.0.0","v2.2.0.5","v2.2.0.4","v2.2.0.3","v2.2.0.2","v2.2.0.1","v2.2.0.0","v2.1.1.2","v2.1.1.1","v2.1.1.0","v2.1.0.9","v2.1.0.8","v2.1.0.7","v2.1.0.6","v2.1.0.5","v2.1.0.4","v2.1.0.3","v2.1.0.2","v2.1.0.1","v2.1.0.0","v2.0.0.1","v1.13.0.0","v1.12.0.2","v1.12.0.1","v1.12.0.0","v1.11.0.0","v1.10.4.3","v1.10.4.2","v1.10.4.1","v1.10.4.0","v1.10.3.2","vpages-test-1700-24092012","vdeployment_test","v1.10.3.1","1.10.3.0","v1.10.2.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13127.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}