PT-2020-7609 · Marked · Marked
Published
2020-01-06
·
Updated
2020-08-31
·
CVE-2014-1850
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
marked versions 0.3.0 and earlier
Description
The issue affects versions of the
marked software, allowing for cross-site scripting attacks through GFM Codeblocks and JavaScript URLs, even when the sanitize option is set to true.Recommendations
Upgrade to version 0.3.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marked