Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qgpv-86r3-87fh

Опубликовано: 30 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-site Scripting in Parsedown

Parsedown version prior to 1.7.0 contains a Cross Site Scripting (XSS) vulnerability in setMarkupEscaped for escaping HTML that can result in JavaScript code execution. This attack appears to be exploitable via specially crafted markdown that allows it to side step HTML escaping by breaking AST boundaries. This vulnerability appears to have been fixed in 1.7.0 and later.

Пакеты

Наименование

erusev/parsedown

composer
Затронутые версииВерсия исправления

< 1.7.0

1.7.0

EPSS

Процентиль: 60%
0.00396
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 8 лет назад

Parsedown version prior to 1.7.0 contains a Cross Site Scripting (XSS) vulnerability in `setMarkupEscaped` for escaping HTML that can result in JavaScript code execution. This attack appears to be exploitable via specially crafted markdown that allows it to side step HTML escaping by breaking AST boundaries. This vulnerability appears to have been fixed in 1.7.0 and later.

EPSS

Процентиль: 60%
0.00396
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79