Vulnerabilities > Chartkick Project > Chartkick > 3.3.2

DATE CVE VULNERABILITY TITLE RISK
2020-08-05 CVE-2020-16254 Injection vulnerability in Chartkick Project Chartkick
The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).
network
low complexity
chartkick-project CWE-74
6.1