CVE-2015-1370
published 2015-01-27CVE-2015-1370: Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.05%
79.1th percentile
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-marked | < node-marked 0.3.6+dfsg-1 (bookworm) | node-marked 0.3.6+dfsg-1 (bookworm) |
| marked_project | marked | <= 0.3.2 | — |
| marked_project | marked | >= 0 < 0.3.3 | 0.3.3 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
VBScript Content Injection in marked
ghsa·2017-10-24
CVE-2015-1370 [MEDIUM] CWE-79 VBScript Content Injection in marked
VBScript Content Injection in marked
Versions 0.3.2 and earlier of `marked` are affected by a cross-site scripting vulnerability even when `sanitize:true` is set.
## Proof of Concept ( IE10 Compatibility Mode Only )
`[xss link](vbscript:alert(1))`
will get a link
`xss link`
## Recommendation
Update to version 0.3.3 or later.
OSV
VBScript Content Injection in marked
osv·2017-10-24
CVE-2015-1370 [MEDIUM] VBScript Content Injection in marked
VBScript Content Injection in marked
Versions 0.3.2 and earlier of `marked` are affected by a cross-site scripting vulnerability even when `sanitize:true` is set.
## Proof of Concept ( IE10 Compatibility Mode Only )
`[xss link](vbscript:alert(1))`
will get a link
`xss link`
## Recommendation
Update to version 0.3.3 or later.
OSV
CVE-2015-1370: Incomplete blacklist vulnerability in marked 0
osv·2015-01-27·CVSS 4.3
CVE-2015-1370 [MEDIUM] CVE-2015-1370: Incomplete blacklist vulnerability in marked 0
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
Debian
CVE-2015-1370: node-marked - Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allow...
vendor_debian·2015·CVSS 4.3
CVE-2015-1370 [MEDIUM] CVE-2015-1370: node-marked - Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allow...
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
Scope: local
bookworm: resolved (fixed in 0.3.6+dfsg-1)
bullseye: resolved (fixed in 0.3.6+dfsg-1)
forky: resolved (fixed in 0.3.6+dfsg-1)
sid: resolved (fixed in 0.3.6+dfsg-1)
trixie: resolved (fixed in 0.3.6+dfsg-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2015/01/23/2https://github.com/chjj/marked/issues/492https://github.com/evilpacket/marked/commit/3c191144939107c45a7fa11ab6cb88be6694a1bahttps://nodesecurity.io/advisories/marked_vbscript_injectionhttp://www.openwall.com/lists/oss-security/2015/01/23/2https://github.com/chjj/marked/issues/492https://github.com/evilpacket/marked/commit/3c191144939107c45a7fa11ab6cb88be6694a1bahttps://nodesecurity.io/advisories/marked_vbscript_injection
2015-01-27
Published