Cross-Site Scripting in react-marked-markdown
High severity
GitHub Reviewed
Published
Sep 1, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 1, 2020
Last updated
Jan 9, 2023
All versions of
react-marked-markdown
are vulnerable to cross-site scripting (XSS) viahref
attributes. This is exploitable if user is provided toreact-marked-markdown
Proof of concept:
Recommendation
No fix is currently available for this vulnerability. It is our recommendation to not install or use this module at this time if you allow user input into href values.
References