Описание
Docsify vulnerable to cross-site scripting due to mishandled encoding
docsify versions 4.12.1 and earlier are vulnerable to cross-site scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the " character.
Пакеты
Наименование
docsify
npm
Затронутые версииВерсия исправления
<= 4.12.1
4.12.2
Связанные уязвимости
CVSS3: 6.1
nvd
почти 5 лет назад
docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the " character.