6.5
CVSSv3

CVE-2018-6806

Published: 07/02/2018 Updated: 11/09/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Marked 2 up to and including 2.5.11 allows remote malicious users to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaScript code, e.g., making XMLHttpRequest calls.

Vulnerable Product Search on Vulmon Subscribe to Product

marked 2 project marked 2