Описание
Cross-site Scripting in Documize
domain/section/markdown/markdown.go in Documize before 3.5.1 mishandles untrusted Markdown content. This was addressed by adding the bluemonday HTML sanitizer to defend against XSS.
Пакеты
Наименование
github.com/documize/community
go
Затронутые версииВерсия исправления
< 3.5.1
3.5.1
Связанные уязвимости
CVSS3: 6.1
nvd
около 6 лет назад
domain/section/markdown/markdown.go in Documize before 3.5.1 mishandles untrusted Markdown content. This was addressed by adding the bluemonday HTML sanitizer to defend against XSS.