MEDIUM 6.1 npm

Multiple Content Injection Vulnerabilities in marked

GHSA-9cw2-jqp5-7x39 · CVE-2014-3743

Published · Modified

Description

Versions 0.3.0 and earlier of marked are affected by two cross-site scripting vulnerabilities, even when sanitize: true is set.

The attack vectors for this vulnerability are GFM Codeblocks and JavaScript URLs.

Recommendation

Upgrade to version 0.3.1 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes