Pi Cross-site Scripting vulnerability
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jul 7, 2023
Description
Published by the National Vulnerability Database
Mar 23, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 7, 2023
Last updated
Jul 7, 2023
A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtration of user-supplied data (preview) passed to the
pi-develop/www/script/editor/markitup/preview/markdown.php
URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.References