Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wvg5-vjpm-h792

Опубликовано: 06 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.

Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.

EPSS

Процентиль: 80%
0.01335
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9.6
nvd
почти 4 года назад

Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.

EPSS

Процентиль: 80%
0.01335
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79