PT-2024-27955 · Codimd+1 · Codimd+1

Ishmeals

+1

·

Published

2024-07-10

·

Updated

2024-09-03

·

CVE-2024-38354

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CodiMD versions prior to 2.5.4
Description The notebook feature of Hackmd.io permits the rendering of iframe HTML tags with an improperly sanitized name attribute. This enables attackers to perform cross-site scripting (XSS) attacks via DOM clobbering.
Recommendations For versions prior to 2.5.4, update to version 2.5.4 to resolve the issue. As a temporary workaround, consider restricting the rendering of iframe HTML tags or sanitizing the name attribute to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-38354
GHSA-22JV-VCH8-2VP9

Affected Products

Codimd
Hackmd.Io