Cross-Site Scripting in editor.md
Moderate severity
GitHub Reviewed
Published
Mar 14, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Mar 14, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
All versions of
editor.mdare vulnerable to Cross-Site Scripting. User input is insufficiently sanitized, allowing attackers to inject malicious code in payloads containing base64-encoded content.Recommendation
No fix is currently available. Consider using an alternative module until a fix is made available.
References