CVE-2017-11593
Dashboard / Vulnerabilities / CVE-2017-11593
CVE-2017-11593
Published: 24 Jul 2017Last Modified: 8 Jul 2026
Summary:
Details: Cross-site scripting (XSS) vulnerability in the Markdown Preview Plus extension before 0.5.7 for Chrome allows remote attackers to inject arbitrary web script or HTML into some web applications via the upload and display of crafted text, markdown, or rst files that are designed to be viewed in the browser as plain text, but that will be converted to HTML without proper sanitization.
References: https://github.com/volca/markdown-preview/issues/60, https://github.com/volca/markdown-preview/commit/1181f044a5457d5e1ac35804ecd84e05977f1920
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 0
Fixed -None
Affected versions
v0.4.6
v0.4.5
v0.4.3
v0.4.2-1
v0.4.2
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
