First published: Mon Mar 21 2022(Updated: )
HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opened with the app, will execute several times.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CKEditor | =1.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24656 is considered a medium severity vulnerability due to its potential for Cross Site Scripting (XSS) attacks.
To fix CVE-2022-24656, upgrade HexoEditor to version 1.1.9 or later, which addresses the XSS vulnerability.
CVE-2022-24656 affects users of HexoEditor version 1.1.8 who open markdown files containing XSS payloads.
CVE-2022-24656 can enable Cross Site Scripting (XSS) attacks, allowing attackers to execute malicious scripts in the context of a user's browser.
The potential risks of CVE-2022-24656 include unauthorized data access, session hijacking, and defacement of web content.