A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: scheme) inside the document may allow an attacker to execute an arbitrary script on the PC of the user using marktext.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: jpcert
Published: 2022-03-07T09:00:35
Updated: 2024-08-03T02:31:59.012Z
Reserved: 2022-02-17T00:00:00
Link: CVE-2022-21158
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-03-10T17:45:09.703
Modified: 2024-11-21T06:44:00.680
Link: CVE-2022-21158
Redhat
No data.