HackMD CodiMD 1.3.1

CPE Details

HackMD CodiMD 1.3.1
1.3.1
2019-10-08
13h40 +00:00
2019-10-08
13h40 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:hackmd:codimd:1.3.1:*:*:*:-:*:*:*

Informations

Vendor

hackmd

Product

codimd

Version

1.3.1

Software Edition

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-38354 2024-07-10 19h49 +00:00 CodiMD allows realtime collaborative markdown notes on all platforms. The notebook feature of Hackmd.io permits the rendering of iframe `HTML` tags with an improperly sanitized `name` attribute. This vulnerability enables attackers to perform cross-site scripting (XSS) attacks via DOM clobbering. This vulnerability is fixed in 2.5.4.
8.1
High
CVE-2019-15499 2019-08-23 01h19 +00:00 CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.
6.1
Medium