PT-2018-16188 · Npm · Markdown-Pdf

CVE-2018-3770

·

Publicado

2018-07-20

·

Atualizado

2023-02-28

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions markdown-pdf versions prior to 9.0.0
Description A path traversal issue in markdown-pdf allows users to insert malicious HTML code, potentially resulting in the reading of local files. The package fails to sanitize HTML code in markdown files, which can lead to Remote Code Execution when markdown files with malicious HTML are converted to PDF. This may allow attackers to execute remote code if the resulting PDF file contains JavaScript code from the original markdown file.
Recommendations For versions prior to 9.0.0, upgrade to version 9.0.0 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3770
GHSA-P7C9-JQHQ-VR3V

Produtos afetados

Markdown-Pdf