Vulnerabilities/

hexo-admin plugin for Node.js XSS Vulnerability

Severity:
Medium

Description

The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
hexo-admin
Anything's wrong? Let us know Last updated on September 26, 2023