Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MarkText<=0.17.1 存在DOM型XSS漏洞 #140

Open
y1ong opened this issue Aug 22, 2023 · 0 comments
Open

MarkText<=0.17.1 存在DOM型XSS漏洞 #140

y1ong opened this issue Aug 22, 2023 · 0 comments
Labels

Comments

@y1ong
Copy link
Owner

y1ong commented Aug 22, 2023

漏洞描述

MarkText 是热门的开源Markdown编辑器,覆盖Windows/Linux/MacOS平台。
MarkText 0.17.1及之前版本中的 pasteCtrl 类未对用户可控的 HTML 内容进行过滤,当用户将攻击者可控的 HTML 代码粘贴至 MarkText 编辑器中时,攻击者可利用DOM型XSS攻击远程执行任意代码。

参考链接

  1. https://www.oscs1024.com/hd/MPS-uvas-0cn2
  2. https://nvd.nist.gov/vuln/detail/CVE-2023-2318
  3. Security Issue: DOM-Based XSS leading to RCE marktext/marktext#3618
  4. https://o.cal1.cn/c3a8d0cbeea8f9ab-marktext-poc/rce.html
@y1ong y1ong added the vuln label Aug 22, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant