hexo-editor@1.0.0 vulnerabilities
A web editor for hexo.
-
latest version
1.0.0
-
first published
9 years ago
-
latest version published
8 years ago
-
licenses detected
- >=0
Direct Vulnerabilities
Known vulnerabilities in the hexo-editor package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
hexo-editor is a web editor for hexo blog platform. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks due to an enabled node integration. If the victim is tricked into pasting such code or open a crafted file in the markdown editor, the attacker will be able to steal user’s data from the computer or perform any actions on the machine that the application running on. PoC by silviavali:
Then, hovering over the word How to fix Cross-site Scripting (XSS)? Ther is no fix version for |
*
|
hexo-editor is a web editor for hexo blog platform. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks due to an enabled node integration. If the victim is tricked into pasting such code or open a crafted file in the markdown editor, the attacker will be able to steal user’s data from the computer or perform any actions on the machine that the application running on. PoC by silviavali:
Then, hovering over the word How to fix Cross-site Scripting (XSS)? Ther is no fix version for |
*
|