PT-2020-21439 · Hexo · Hexo-Admin
Published
2020-09-03
·
Updated
2020-09-03
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
hexo-admin versions (all versions)
Description
The issue concerns a failure to sanitize rendered markdown, which allows attackers to execute arbitrary JavaScript in a victim's browser if they can create new posts. This is a Cross-Site Scripting (XSS) issue.
Recommendations
Consider using an alternative package until a fix is made available.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hexo-Admin