Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfjh-p3g4-3q2f

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

VBScript Content Injection in marked

Versions 0.3.2 and earlier of marked are affected by a cross-site scripting vulnerability even when sanitize:true is set.

Proof of Concept ( IE10 Compatibility Mode Only )

[xss link](vbscript:alert(1))

will get a link

<a href="vbscript:alert(1)">xss link</a>

Recommendation

Update to version 0.3.3 or later.

Пакеты

Наименование

marked

npm
Затронутые версииВерсия исправления

< 0.3.3

0.3.3

EPSS

Процентиль: 57%
0.00349
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 11 лет назад

Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.

nvd
около 11 лет назад

Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.

debian
около 11 лет назад

Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Nod ...

EPSS

Процентиль: 57%
0.00349
Низкий

Дефекты

CWE-79