Description
All versions of react-marked-markdown are vulnerable to cross-site scripting (XSS) via href attributes. This is exploitable if user is provided to react-marked-markdown
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Cross-Site Scripting in react-marked-markdown and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-Site Scripting in marked - Vulnerability
- Cross-site Scripting in @spscommerce/ds-react - Vulnerability
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-markdown-gfm - CVE-2022-31175
- react-query-streamed-hydration Cross-site Scripting vulnerability - CVE-2024-24558
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


