PT-2020-21403 · Npmcorp · Marky-Markdown
Published
2020-09-03
·
Updated
2020-09-03
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
marky-markdown versions (all versions)
Description
The issue concerns HTML Injection due to the failure to sanitize
style attributes in img tags of the markdown input. This may allow attackers to affect the size of images in the rendered HTML.Recommendations
For all versions, upgrade to @npmcorp/marky-markdown, as the original package is no longer maintained.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marky-Markdown