PT-2018-5255 · Shiba · Shiba Markdown Live Preview App
Silviavali
·
Published
2018-01-03
·
Updated
2022-05-14
·
CVE-2017-1000491
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Shiba markdown live preview app version 1.1.0
Description
The issue allows for XSS, leading to code execution due to enabled node integration.
Recommendations
For version 1.1.0, disable node integration to prevent code execution until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shiba Markdown Live Preview App