PT-2018-17138 · Markdown2 · Markdown2

Vin01

·

Publicado

2018-01-18

·

Atualizado

2024-07-12

·

CVE-2018-5773

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: markdown2 versions through 2.3.5
Description: The issue concerns a flaw in the safe mode feature of markdown2, which is intended to sanitize user input against XSS attacks. However, this feature does not properly escape input, allowing for the potential triggering of XSS with a crafted payload. This can be demonstrated by omitting the final > character from an IMG tag, showcasing the feature's inability to correctly handle such input.
Recommendations: For versions through 2.3.5, consider disabling the safe mode feature until a proper fix is available, as it does not provide the intended protection against XSS attacks. Additionally, restricting user input to prevent the inclusion of potentially malicious HTML tags, such as IMG tags without a closing >, can help minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-5773
GHSA-P6H9-GW49-RQM4
OPENSUSE-SU-2024:11237-1
OPENSUSE-SU-2024:14146-1
PYSEC-2018-13

Produtos afetados

Markdown2