CVE-2020-27176

Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, which parses HTML even though HTML support is not one of the primary advertised roles of the product.
References
Link Resource
https://github.com/marktext/marktext/issues/2360 Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:marktext:marktext:*:*:*:*:*:*:*:*

Information

Published : 2020-10-15 22:15

Updated : 2020-10-26 10:10


NVD link : CVE-2020-27176

Mitre link : CVE-2020-27176


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

marktext

  • marktext