Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-29503

Опубликовано: 19 мая 2021
Источник: nvd
CVSS3: 8.1
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scripting attack using the YAML-metadata of a note. An attacker with write access to a note can embed HTML tags in the Open Graph metadata section of the note, resulting in the frontend rendering the script tag as part of the <head> section. Unless your instance prevents guests from editing notes, this vulnerability allows unauthenticated attackers to inject JavaScript into notes that allow guest edits. If your instance prevents guests from editing notes, this vulnerability allows authenticated attackers to inject JavaScript into any note pages they have write-access to. This vulnerability is patched in version 1.8.2. As a workaround, one can disable guest edits until the next update.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hedgedoc:hedgedoc:*:*:*:*:*:*:*:*
Версия до 1.8.2 (исключая)

EPSS

Процентиль: 83%
0.02049
Низкий

8.1 High

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-80
CWE-79

EPSS

Процентиль: 83%
0.02049
Низкий

8.1 High

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-80
CWE-79