ZeroHour

CVE-2021-25987

CVSS 3.1
4.6 medium
EPSS
<1%p26
Published
()
Modified
Description

Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.

Vendors
hexo
Products
hexo
Weakness
CWE-79
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.