MEDIUM 6.1 npm
Multiple Content Injection Vulnerabilities in marked
GHSA-9cw2-jqp5-7x39 · CVE-2014-3743
Published · Modified
Description
Versions 0.3.0 and earlier of marked are affected by two cross-site scripting vulnerabilities, even when sanitize: true is set.
The attack vectors for this vulnerability are GFM Codeblocks and JavaScript URLs.
Recommendation
Upgrade to version 0.3.1 or later.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes