6.1
CVSSv3

CVE-2018-5773

CVSSv4: NA | CVSSv3: 6.1 | CVSSv2: 4.3 | VMScore: 710 | EPSS: 0.00262 | KEV: Not Included
Published: 18/01/2018 Updated: 21/11/2024

Vulnerability Summary

An issue exists in markdown2 (aka python-markdown2) up to and including 2.3.5. The safe_mode feature, which is supposed to sanitize user input against XSS, is flawed and does not escape the input properly. With a crafted payload, XSS can be triggered, as demonstrated by omitting the final '>' character from an IMG tag.

Vulnerable Product Search on Vulmon Subscribe to Product

python-markdown2 project python-markdown2