Vulnerability Details CVE-2024-21535
Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.6%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2024-21535
-
cpe:2.3:a:quantizor:markdown-to-jsx:-
-
cpe:2.3:a:quantizor:markdown-to-jsx:1.0.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:1.1.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:1.2.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:2.0.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:3.0.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:3.1.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:3.1.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:4.0.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:4.0.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:4.0.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:4.0.3
-
cpe:2.3:a:quantizor:markdown-to-jsx:5.0.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:5.0.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:5.1.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:5.2.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:5.3.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:5.3.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:5.3.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:5.3.3
-
cpe:2.3:a:quantizor:markdown-to-jsx:5.4.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:5.4.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:5.4.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.0.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.0.3
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.1.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.1.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.1.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.1.3
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.1.4
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.10.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.10.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.10.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.10.3
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.11.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.11.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.11.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.11.4
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.2.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.2.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.2.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.3.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.3.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.3.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.4.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.4.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.5.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.5.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.5.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.6.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.6.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.6.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.6.3
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.6.4
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.6.5
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.6.6
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.6.7
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.6.8
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.6.9
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.7.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.7.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.7.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.7.3
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.7.4
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.8.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.8.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.8.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.8.3
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.8.4
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.9.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.9.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.9.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.9.3
-
cpe:2.3:a:quantizor:markdown-to-jsx:6.9.4
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.0.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.0.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.1.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.1.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.1.2
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.1.3
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.1.4
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.1.5
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.1.6
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.1.7
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.1.8
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.1.9
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.2.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.2.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.3.0
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.3.1
-
cpe:2.3:a:quantizor:markdown-to-jsx:7.3.2