Описание
Note Mark is a web-based Markdown notes app. A stored cross-site scripting (XSS) vulnerability in Note Mark allows attackers to execute arbitrary web scripts via a crafted payload injected into the URL value of a link in the markdown content. This vulnerability is fixed in 0.13.1.
Ссылки
- Patch
- ExploitVendor Advisory
- Patch
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.13.1 (исключая)
cpe:2.3:a:enchantedcode:note_mark:*:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.02012
Низкий
8.7 High
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79
EPSS
Процентиль: 83%
0.02012
Низкий
8.7 High
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79