Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p6h9-gw49-rqm4

Опубликовано: 12 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

markdown2 is vulnerable to cross-site scripting

An issue was discovered in markdown2 (aka python-markdown2) through 2.3.5. The safe_mode feature, which is supposed to sanitize user input against XSS, is flawed and does not escape the input properly. With a crafted payload, XSS can be triggered, as demonstrated by omitting the final > character from an IMG tag.

Пакеты

Наименование

markdown2

pip
Затронутые версииВерсия исправления

< 2.3.6

2.3.6

EPSS

Процентиль: 58%
0.00358
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 8 лет назад

An issue was discovered in markdown2 (aka python-markdown2) through 2.3.5. The safe_mode feature, which is supposed to sanitize user input against XSS, is flawed and does not escape the input properly. With a crafted payload, XSS can be triggered, as demonstrated by omitting the final '>' character from an IMG tag.

EPSS

Процентиль: 58%
0.00358
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79