PT-2020-21439 · Hexo · Hexo-Admin

Published

2020-09-03

·

Updated

2020-09-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions hexo-admin versions (all versions)
Description The issue concerns a failure to sanitize rendered markdown, which allows attackers to execute arbitrary JavaScript in a victim's browser if they can create new posts. This is a Cross-Site Scripting (XSS) issue.
Recommendations Consider using an alternative package until a fix is made available.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-PHPH-XPJ4-WVCV

Affected Products

Hexo-Admin