Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2019-9844
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.004
EPSS Ranking
58.7%
CVSS Severity
CVSS v3 Score
6.1
CVSS v2 Score
4.3
References
https://github.com/Khan/simple-markdown/pull/63
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JFLP3KJVSV5VWMNEBRXLGRVYFXOV5KOG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZG2I7VH7WLSEUQ77KYP5CRAVFT2RK2U/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5EFW655O3BXZYAPB65XEREXB2DSNSOT/
https://www.npmjs.com/package/simple-markdown/v/0.4.4
https://github.com/Khan/simple-markdown/pull/63
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JFLP3KJVSV5VWMNEBRXLGRVYFXOV5KOG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZG2I7VH7WLSEUQ77KYP5CRAVFT2RK2U/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5EFW655O3BXZYAPB65XEREXB2DSNSOT/
https://www.npmjs.com/package/simple-markdown/v/0.4.4
Products affected by CVE-2019-9844
Khanacademy
»
Simple-Markdown
»
Version:
0.0.9
cpe:2.3:a:khanacademy:simple-markdown:0.0.9
Khanacademy
»
Simple-Markdown
»
Version:
0.1.0
cpe:2.3:a:khanacademy:simple-markdown:0.1.0
Khanacademy
»
Simple-Markdown
»
Version:
0.1.1
cpe:2.3:a:khanacademy:simple-markdown:0.1.1
Khanacademy
»
Simple-Markdown
»
Version:
0.2.2
cpe:2.3:a:khanacademy:simple-markdown:0.2.2
Khanacademy
»
Simple-Markdown
»
Version:
0.3.0
cpe:2.3:a:khanacademy:simple-markdown:0.3.0
Khanacademy
»
Simple-Markdown
»
Version:
0.3.1
cpe:2.3:a:khanacademy:simple-markdown:0.3.1
Khanacademy
»
Simple-Markdown
»
Version:
0.3.2
cpe:2.3:a:khanacademy:simple-markdown:0.3.2
Khanacademy
»
Simple-Markdown
»
Version:
0.3.3
cpe:2.3:a:khanacademy:simple-markdown:0.3.3
Khanacademy
»
Simple-Markdown
»
Version:
0.4.0
cpe:2.3:a:khanacademy:simple-markdown:0.4.0
Khanacademy
»
Simple-Markdown
»
Version:
0.4.2
cpe:2.3:a:khanacademy:simple-markdown:0.4.2
Khanacademy
»
Simple-Markdown
»
Version:
0.4.3
cpe:2.3:a:khanacademy:simple-markdown:0.4.3
Fedoraproject
»
Fedora
»
Version:
30
cpe:2.3:o:fedoraproject:fedora:30
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved