PHP League CommonMark vulnerable to Cross-Site Scripting (XSS)
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 6, 2024
Description
Published by the National Vulnerability Database
Dec 30, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Sep 12, 2022
Last updated
Feb 6, 2024
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as javascri%0apt).
References