PT-2018-17138 · Markdown2 · Markdown2

Vin01

·

Published

2018-01-18

·

Updated

2024-07-12

·

CVE-2018-5773

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: markdown2 versions through 2.3.5
Description: The issue concerns a flaw in the safe mode feature of markdown2, which is intended to sanitize user input against XSS attacks. However, this feature does not properly escape input, allowing for the potential triggering of XSS with a crafted payload. This can be demonstrated by omitting the final > character from an IMG tag, showcasing the feature's inability to correctly handle such input.
Recommendations: For versions through 2.3.5, consider disabling the safe mode feature until a proper fix is available, as it does not provide the intended protection against XSS attacks. Additionally, restricting user input to prevent the inclusion of potentially malicious HTML tags, such as IMG tags without a closing >, can help minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5773
GHSA-P6H9-GW49-RQM4
OPENSUSE-SU-2024:11237-1
OPENSUSE-SU-2024:14146-1
PYSEC-2018-13

Affected Products

Markdown2