Логотип exploitDog
bind:CVE-2020-7680
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-7680

Количество 2

Количество 2

nvd логотип

CVE-2020-7680

больше 5 лет назад

docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qpqh-46qj-vwcw

больше 4 лет назад

Cross-site Scripting in docsify

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-7680

docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.

CVSS3: 6.1
3%
Низкий
больше 5 лет назад
github логотип
GHSA-qpqh-46qj-vwcw

Cross-site Scripting in docsify

CVSS3: 6.1
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу