UNKNOWN npm
VBScript Content Injection in marked
GHSA-cfjh-p3g4-3q2f · CVE-2015-1370
Published · Modified
Description
Versions 0.3.2 and earlier of marked are affected by a cross-site scripting vulnerability even when sanitize:true is set.
Proof of Concept ( IE10 Compatibility Mode Only )
[xss link](vbscript:alert(1))
will get a link
<a href="vbscript:alert(1)">xss link</a>
Recommendation
Update to version 0.3.3 or later.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2015-1370
- WEB https://github.com/chjj/marked/issues/492
- WEB https://github.com/markedjs/marked/issues/492
- WEB https://github.com/evilpacket/marked/commit/3c191144939107c45a7fa11ab6cb88be6694a1ba
- WEB https://github.com/markedjs/marked/commit/fc372d1c6293267722e33f2719d57cebd67b3da1
- PACKAGE https://github.com/markedjs/marked
- WEB https://www.npmjs.com/advisories/24
- WEB https://www.npmjs.com/advisories/24/versions
- WEB http://www.openwall.com/lists/oss-security/2015/01/23/2
Ready to move
Start Securing
Free, no credit card | First findings in minutes