Описание
hexo-admin plugin for Node.js XSS Vulnerability
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
Пакеты
Наименование
hexo-admin
npm
Затронутые версииВерсия исправления
<= 2.3.0
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
больше 6 лет назад
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.