Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-36080: Prevent Cross-site Scripting when editing makdown file

Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, an attacker could capture user’s session cookies or execute malicious Javascript when a victim edits a markdown file. Version 1.7.1 fixes this issue.

CVE
#xss#java

High

Linbreux published GHSA-9m4m-6gqx-gfj3

Sep 4, 2022

Package

wiki.py (wikmd)

Affected versions

< 1.7.0

Patched versions

>= 1.7.1

Description

Impact

An attacker could capture user’s session cookies or execute malicious Javascript

Severity

High

CVE ID

CVE-2022-36080

Weaknesses

CWE-79

Credits

  • Mephue

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907