PT-2018-9595 · Cebe · Cebe Markdown Parser
Ekultek
·
Published
2018-12-20
·
Updated
2024-08-05
·
CVE-2018-1000874
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
cebe markdown parser versions 1.2.0 and earlier
Description:
The issue allows a maliciously crafted script to be executed, potentially resulting in the loss of user data and sensitive user information. This can be exploited by crafting a three backtick wrapped payload with a character in front, such as "
<script>alert();</script>".Recommendations:
For cebe markdown parser versions 1.2.0 and earlier, consider sanitizing user input to prevent malicious code execution until a fix is available. As a temporary workaround, restrict the use of the markdown parser for untrusted input to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cebe Markdown Parser