Content Injection in remarkable
High severity
GitHub Reviewed
Published
Aug 31, 2020
to the GitHub Advisory Database
•
Updated Apr 3, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Aug 31, 2020
Last updated
Apr 3, 2023
Versions 1.4.0 and earlier of
remarkable
are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions ofremarkable
did not properly whitelist link protocols, and consequently allowedjavascript:
to be used.Proof of Concept
Markdown Source:
Rendered HTML:
Recommendation
Update to version 1.4.1 or later
References