Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27176

Опубликовано: 16 окт. 2020
Источник: nvd
CVSS3: 8.3
CVSS3: 9.6
CVSS2: 6.8
EPSS Низкий

Описание

Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, which parses HTML even though HTML support is not one of the primary advertised roles of the product.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:marktext:marktext:*:*:*:*:*:*:*:*
Версия до 0.16.2 (включая)

EPSS

Процентиль: 79%
0.0129
Низкий

8.3 High

CVSS3

9.6 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
больше 3 лет назад

Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, which parses HTML even though HTML support is not one of the primary advertised roles of the product.

EPSS

Процентиль: 79%
0.0129
Низкий

8.3 High

CVSS3

9.6 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-79