Vulnerabilities/

Cross-site Scripting in vmd

Severity:
Medium

Description

vmd through 1.34.0 allows div class="markdown-body" XSS, as demonstrated by Electron remote code execution via require('child_process').execSync('calc.exe') on Windows and a similar attack on macOS.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
vmd
Anything's wrong? Let us know Last updated on September 11, 2023

This issue is available in SmartScanner Professional

See Pricing