Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wx3-54gh-9fr9

Опубликовано: 15 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Cross site scripting in markdown-to-jsx

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.

Пакеты

Наименование

markdown-to-jsx

npm
Затронутые версииВерсия исправления

< 7.4.0

7.4.0

EPSS

Процентиль: 35%
0.00145
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 1 года назад

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.

CVSS3: 6.1
redhat
больше 1 года назад

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.

CVSS3: 6.1
nvd
больше 1 года назад

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.

CVSS3: 6.1
debian
больше 1 года назад

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to ...

EPSS

Процентиль: 35%
0.00145
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79