Vulnerabilities
Vulnerable Software
Quantizor:  Security Vulnerabilities
Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.
CVSS Score
6.1
EPSS Score
0.0
Published
2024-10-15


Contact Us

Shodan ® - All rights reserved