Markdown-Nice v1.8.22 vulnerable to Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
Sep 10, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Sep 9, 2022
Published to the GitHub Advisory Database
Sep 10, 2022
Reviewed
Sep 15, 2022
Last updated
Feb 2, 2023
A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.
References