Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-62m3-fc7f-jpp8

Опубликовано: 26 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Parsedown Class-Name Injection

Parsedown before 1.7.2, when safe mode is used and HTML markup is disabled, might allow attackers to execute arbitrary JavaScript code if a script (already running on the affected page) executes the contents of any element with a specific class. This occurs because spaces are permitted in code block infostrings, which interferes with the intended behavior of a single class name beginning with the language- substring.

Пакеты

Наименование

erusev/parsedown

composer
Затронутые версииВерсия исправления

< 1.7.2

1.7.2

EPSS

Процентиль: 66%
0.00521
Низкий

8.1 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.1
nvd
почти 7 лет назад

Parsedown before 1.7.2, when safe mode is used and HTML markup is disabled, might allow attackers to execute arbitrary JavaScript code if a script (already running on the affected page) executes the contents of any element with a specific class. This occurs because spaces are permitted in code block infostrings, which interferes with the intended behavior of a single class name beginning with the language- substring.

EPSS

Процентиль: 66%
0.00521
Низкий

8.1 High

CVSS3

Дефекты

CWE-79