Mark Text v0.16.3 was discovered to contain a DOM-based...
Critical severity
Unreviewed
Published
Mar 6, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Mar 5, 2022
Published to the GitHub Advisory Database
Mar 6, 2022
Last updated
Feb 3, 2023
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.
References