Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-11888
HistoryApr 20, 2020 - 4:15 p.m.

Cross site scripting

2020-04-2016:15:00
PRIOn knowledge base
www.prio-n.com
2

5.8 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.3%

python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.

CPENameOperatorVersion
python-markdown2le2.3.8

5.8 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.3%