CVE-2019-14517: XSS
Published Aug 1, 2019
·Updated
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
Affected Software
1 affected component
Editor.md Project Editor.md=1.5.0
Event History
Aug 1, 2019
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14517?
CVE-2019-14517 is classified as a high severity vulnerability due to its potential for exploitation via cross-site scripting (XSS).
2
How do I fix CVE-2019-14517?
To fix CVE-2019-14517, upgrade to a version of Editor.md that is later than 1.5.0 that addresses this vulnerability.
3
What type of attack does CVE-2019-14517 facilitate?
CVE-2019-14517 facilitates cross-site scripting (XSS) attacks which can lead to unauthorized access or data exposure.
4
Which versions of Editor.md are affected by CVE-2019-14517?
CVE-2019-14517 affects the Editor.md version 1.5.0 specifically.
5
Can CVE-2019-14517 be exploited remotely?
Yes, CVE-2019-14517 can be exploited remotely by injecting malicious JavaScript into web pages that use Editor.md.