Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25052
HistoryApr 21, 2020 - 1:42 a.m.

Cross-Site Scripting (XSS)

2020-04-2101:42:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.004 Low

EPSS

Percentile

72.3%

markdown2 is vulnerable to cross-site scripting (XSS) attacks. The vulnerability is introduced by an incomplete fix to properly encode ampersands and angle brackets in the function _encode_amps_and_angles,allowing an attacker to inject arbitrary Javascript into a victim’s browser.

CPENameOperatorVersion
markdown2le2.3.8