Описание
markdown-it-decorate vulnerable to cross-site scripting (XSS)
markdown-it-decorate adds attributes, IDs and classes to Markdown, and the most recent version 1.2.2 was published in 2017. All versions are currently vulnerable to cross-site scripting (XSS) and there is no fixed version at this time
Пакеты
Наименование
markdown-it-decorate
npm
Затронутые версииВерсия исправления
<= 1.2.2
Отсутствует
Связанные уязвимости
CVSS3: 7.3
nvd
больше 3 лет назад
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.