First published: Wed Mar 13 2019(Updated: )
DOM-based XSS exists in 1024Tools Markdown 1.0 via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usualtool CMS | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9736 has a medium severity rating due to the potential for DOM-based cross-site scripting attacks.
To fix CVE-2019-9736, update to a version of 1024Tools Markdown that addresses this vulnerability.
CVE-2019-9736 can lead to unauthorized script execution in a user's browser, compromising data and user sessions.
CVE-2019-9736 specifically affects version 1.0 of 1024Tools Markdown.
Any users or applications using version 1.0 of 1024Tools Markdown are at risk of CVE-2019-9736.