CVE-2022-38639

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in npm/markdown-nice

Identifiers

GHSA-462r-wxvm-jvxh, CVE-2022-38639

Package Slug

npm/markdown-nice

Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.

Affected Versions

All versions up to 1.8.22

Solution

Unfortunately, there is no solution available yet.

Last Modified

2022-09-15

source