Description
A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of the component Markdown Handler. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
In Changsha Developer Technology iView Editor up to 1.1.1 ist eine Schwachstelle entdeckt worden. Das betrifft eine unbekannte Funktionalität der Komponente Markdown Handler. Die Manipulation führt zu cross site scripting. Der Angriff kann über das Netzwerk angegangen werden. Die Ausnutzung wurde veröffentlicht und kann verwendet werden.
Problem types
Product status
1.1.1
Timeline
2025-09-25: | Advisory disclosed |
2025-09-25: | VulDB entry created |
2025-09-25: | VulDB entry last update |
Credits
suc2es2 (VulDB User)
References
vuldb.com/?id.325819 (VDB-325819 | Changsha Developer Technology iView Editor Markdown cross site scripting)
vuldb.com/?ctiid.325819 (VDB-325819 | CTI Indicators (IOB, IOC, TTP))
vuldb.com/?submit.652402 (Submit #652402 | Changsha Developer Technology Co., Ltd. iView Editor <=1.1.1 XSS vulnerability)
github.com/duckpigdog/CVE/blob/main/iView Editor XSS.docx