Description
Markdown Explorer 0.1.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through file uploads and editor inputs. Attackers can upload markdown files with embedded JavaScript payloads that execute in the application's privileged renderer context, allowing code execution on the host.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
TaurusOmar
References
www.vulncheck.com/...xplorer-persistent-cross-site-scripting
www.exploit-db.com/exploits/49826 (ExploitDB-49826)
github.com/jersou/markdown-explorer (Markdown Explorer GitHub Repository)
imgur.com/a/w4bcPWs (Proof of Concept Video)
www.vulncheck.com/...xplorer-persistent-cross-site-scripting (VulnCheck Advisory: Markdown Explorer 0.1.1 - Persistent Cross-Site Scripting)