Khanacademy Simple-Markdown vulnerabilities
3 known vulnerabilities affecting khanacademy/simple-markdown.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-25103HIGHCVSS 7.5v0.5.12023-02-12
CVE-2019-25103 [HIGH] CWE-1333 CVE-2019-25103: A vulnerability has been found in simple-markdown 0.5.1 and classified as problematic. Affected by t
A vulnerability has been found in simple-markdown 0.5.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file simple-markdown.js. The manipulation leads to inefficient regular expression complexity. The attack can be launched remotely. Upgrading to version 0.5.2 is able to address this issue. The patch
ghsanvdosv
CVE-2019-25102HIGHCVSS 7.5v0.6.02023-02-12
CVE-2019-25102 [HIGH] CWE-1333 CVE-2019-25102: A vulnerability, which was classified as problematic, was found in simple-markdown 0.6.0. Affected i
A vulnerability, which was classified as problematic, was found in simple-markdown 0.6.0. Affected is an unknown function of the file simple-markdown.js. The manipulation with the input <<<<<<<<<<:/:/:/:/:/:/:/:/:/:/ leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The exploit has been disclosed to the
ghsanvdosv
CVE-2019-9844MEDIUMCVSS 6.1fixed in 0.4.42019-04-09
CVE-2019-9844 [MEDIUM] CWE-79 CVE-2019-9844: simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript:
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
ghsanvdosv