Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7122
HistoryJul 23, 2018 - 4:20 a.m.

Cross-site Scripting (XSS)

2018-07-2304:20:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.001 Low

EPSS

Percentile

26.5%

markdown-pdf is vulnerable to cross-site scripting (XSS) attacks. The application does not properly sanitize user input, allowing a malicious user can pass a markdown file to the application to inject and execute arbitrary HTML code.

CPENameOperatorVersion
markdown-pdfle8.1.1
markdown-pdfle8.1.1

0.001 Low

EPSS

Percentile

26.5%