Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaScript code, e.g., making XMLHttpRequest calls.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Marked 信息泄露漏洞
Vulnerability Description
Marked是美国软件开发者Christopher Jeffrey所研发的一款使用JavaScript编写的Markdown解析器和编译器。 Marked 2 2.5.11及之前版本中存在信息泄露漏洞。远程攻击者可借助特制的HTML文档利用该漏洞读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A