Impact
The flaw resides in the Markdown.toHtml function of the Page Content Rendering component in itranswarp. By supplying crafted Markdown input, an attacker can cause the function to produce output that includes arbitrary HTML and JavaScript, which The vulnerability is a cross‑site scripting flaw that can be triggered remotely, and an exploit has already been published.
Affected Systems
This vulnerability affects only the itranswarp product released by michaelliao, specifically versions up to and including 2.19. Versions newer than 2.19 are not known to be vulnerable, and the maintainers have not yet released a patch for the affected releases.
Risk and Exploitability
The CVSS base score of 5.1 suggests a moderate impact. The EPSS score is below 1 %, indicating a very low expected exploitation probability at this time. The vulnerability is not listed in the CISA KEV catalog. However, because the flaw is exploitable remotely and an exploit is publicly available, systems that remain on the vulnerable versions face a meaningful risk of cross‑site scripting attacks.
OpenCVE Enrichment