{"id":"CVE-2019-13127","details":"An issue was discovered in mxGraph through 4.0.0, related to the \"draw.io Diagrams\" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.","aliases":["GHSA-xm59-jvxm-cp3v"],"modified":"2026-05-16T04:01:46.188249006Z","published":"2019-07-01T15:15:11.647Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:draw:draw.io_diagrams:*:*:*:*:*:confluence:*:*"],"extracted_events":[{"fixed":"8.3.14"}],"source":"CPE_FIELD","vendor_product":"draw:draw.io_diagrams"}]},"references":[{"type":"ADVISORY","url":"https://marketplace.atlassian.com/apps/1210933/draw-io-diagrams-for-confluence/version-history"},{"type":"FIX","url":"https://github.com/jgraph/mxgraph/commit/76e8e2809b622659a9c5ffdc4f19922b7a68cfa3"},{"type":"EVIDENCE","url":"https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-032.txt"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}