Описание
HyperDown vulnerable to Cross-site Scripting
HyperDown is a markdown parser written for the Chinese website SegmentFault. Improper validation of the href attribute allows for Cross-site Scripting. At publication there are no patched versions, and no known workarounds.
Пакеты
Наименование
joyqi/hyper-down
composer
Затронутые версииВерсия исправления
<= 2.4.27
Отсутствует
Связанные уязвимости
CVSS3: 5.4
nvd
больше 3 лет назад
The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.