CVE-2014-10065
EPSS 0.24%Content Injection in remarkable
發布日:2020/8/31修改日:2023/11/8
描述
Versions 1.4.0 and earlier of `remarkable` are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions of `remarkable` did not properly whitelist link protocols, and consequently allowed `javascript:` to be used. ### Proof of Concept Markdown Source: ``` [link](<javascript:alert(1)>) ``` Rendered HTML: ``` <a href="javascript:alert(1)">link</a> ``` ## Recommendation Update to version 1.4.1 or later
受影響套件(1)
- npm/remarkablefrom 0, < 1.4.1