CVE-2020-19952
PoC —CVSS 3.1
6.1 medium
EPSS
<1%p50
Published
()
Modified
Description
Cross Site Scripting (XSS) vulnerability in Rendering Engine in jbt Markdown Editor thru commit 2252418c27dffbb35147acd8ed324822b8919477, allows remote attackers to execute arbirary code via crafted payload or opening malicious .md file.
- Vendors
- jbt
- Products
- live \(github-flavored\) markdown editor
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.