Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Parsedown before 1.7.2, when safe mode is used and HTML markup is disabled, might allow attackers to execute arbitrary JavaScript code if a script (already running on the affected page) executes the contents of any element with a specific class. This occurs because spaces are permitted in code block infostrings, which interferes with the intended behavior of a single class name beginning with the language- substring.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Parsedown 代码注入漏洞
Vulnerability Description
Parsedown是一款基于PHP的Markdown标记语言解析器。 Parsedown 1.7.2之前版本中存在代码注入漏洞。攻击者可利用该漏洞执行任意的脚本代码。
CVSS Information
N/A
Vulnerability Type
N/A