CVE-2025-60312: XSS
Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" field, allowing a remote attacker to inject arbitrary HTML/JavaScript code that executes in the victim's browser upon clicking the "Convert to HTML" button.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60312?
CVE-2025-60312 is classified as a medium-severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-60312?
To fix CVE-2025-60312, implement proper input sanitization and validation in the "Markdown Input" field to prevent XSS attacks.
What type of vulnerability is CVE-2025-60312?
CVE-2025-60312 is a Cross-Site Scripting (XSS) vulnerability affecting the Markdown to HTML Converter.
Who is affected by CVE-2025-60312?
CVE-2025-60312 affects users of the Sourcecodester Markdown to HTML Converter version 1.0.
What could an attacker achieve with CVE-2025-60312?
An attacker exploiting CVE-2025-60312 could execute arbitrary HTML or JavaScript code in the browsers of users who interact with the application.