CVE-2015-1370

Updated on 27 Jan 2015

Severity

Awaiting Analysis

Details

CVSS score
8.6

Overview

About vulnerability

Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.

Details

Affected product:
Acorn , marked
Affected packages:
marked @ 0.2.10 (+1 more)
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.

Fixes