Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-95952
HistoryDec 01, 2021 - 12:00 a.m.

Hexo cross-site scripting vulnerability

2021-12-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
hexo
cross-site scripting
vulnerability
data validation
filtering
user-supplied data
javascript code
client side
tommy chen
china
blogging framework
exploit
cnvd

EPSS

0

Percentile

12.6%

Hexo is a fast, simple and powerful blogging framework from the personal developer Tommy Chen in China. Hexo suffers from a cross-site scripting vulnerability that stems from Hexo’s lack of data validation filtering of user-supplied data and output. An attacker could exploit this vulnerability to execute JavaScript code on the client side.

EPSS

0

Percentile

12.6%