PT-2021-11237 · Mdbook · Mdbook
Kamil Vavra
·
Published
2021-01-04
·
Updated
2021-08-25
·
CVE-2020-26297
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
mdBook versions prior to 0.4.5
Description:
The search feature of mdBook is affected by a cross-site scripting vulnerability, which could allow an attacker to execute arbitrary JavaScript code on a user's browser. This can be achieved by tricking the user into typing a malicious search query or clicking a link to the search page with the malicious search query prefilled. The vulnerability was introduced in version 0.1.4 and is fixed in mdBook 0.4.5 by properly escaping the search query.
Recommendations:
For mdBook versions prior to 0.4.5, upgrade to mdBook 0.4.5 or greater and rebuild website contents with it. As a temporary workaround, consider restricting access to the search feature until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mdbook