Security Advisory

CVE-2025-46654

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-04-26 00:00:00
Last updated 2025-04-29 15:22:49
Assigner mitre
State PUBLISHED

Description

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.