Showdown 2.1.0 及之前版本在 链接和图像子解析器中存在跨站脚本(XSS)漏洞。这些子解析器未对目标 URL 中的双引号进行转义,当这些 URL 被嵌入到 和 属性时,便会产生安全风险。攻击者可构造包含双引号后紧跟 或 事件处理程序的 Markdown 链接或图像语法,当受害者查看渲染后的 HTML 内容时,即可执行恶意脚本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| showdownjs | showdown | ≤ 2.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| showdownjs | showdown | 0 ~ 2.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet