CVE-2022-25849

The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.
References
Link Resource
https://security.snyk.io/vuln/SNYK-PHP-JOYQIHYPERDOWN-2953544 Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:hyperdown_project:hyperdown:*:*:*:*:*:node.js:*:*

Information

Published : 2022-10-26 05:15

Updated : 2022-11-03 01:59


NVD link : CVE-2022-25849

Mitre link : CVE-2022-25849

Products Affected
No products.
CWE