Описание
markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped
This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.
Пакеты
Наименование
markdown-it-toc
npm
Затронутые версииВерсия исправления
<= 1.1.0
Отсутствует
Связанные уязвимости
CVSS3: 7.3
nvd
больше 3 лет назад
This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.