PT-2023-16559 · Unknown · Markdown-Pdf

Carlos Bello

·

Published

2023-04-04

·

Updated

2023-04-13

·

CVE-2023-0835

CVSS v3.1

8.2

High

AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions markdown-pdf version 11.0.0
Description The issue allows an external attacker to remotely obtain arbitrary local files due to the application's failure to validate the Markdown content entered by the user.
Recommendations For markdown-pdf version 11.0.0, update to a version that includes input validation for Markdown content to prevent unauthorized access to local files.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-0835
GHSA-QGHR-877H-F9JH

Affected Products

Markdown-Pdf