Beveiligingsadvies

CVE-2022-25849

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-10-26 05:05:09
Laatst bijgewerkt 2025-05-09 19:09:38
Toegewezen door snyk
CVSS-score 5.4
Status PUBLISHED

Beschrijving

The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.