First published: Fri Mar 15 2019(Updated: )
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Khan Academy Simple Markdown | <0.4.4 | |
Fedora | =30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9844 has a medium severity level due to its potential for XSS attacks.
To fix CVE-2019-9844, upgrade simple-markdown.js to version 0.4.4 or later.
CVE-2019-9844 contains cross-site scripting (XSS) vulnerabilities via data: or vbscript: URIs.
Versions of Khan Academy simple-markdown before 0.4.4 and Fedora 30 are affected by CVE-2019-9844.
Yes, CVE-2019-9844 can impact web applications that utilize the affected versions of simple-markdown.js, potentially allowing XSS attacks.