384
VMScore

CVE-2020-26297

Published: 04/01/2021 Updated: 14/01/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

mdBook is a utility to create modern online books from Markdown files and is written in Rust. In mdBook before version 0.4.5, there is a vulnerability affecting the search feature of mdBook, which could allow an malicious user to execute arbitrary JavaScript code on the page. The search feature of mdBook (introduced in version 0.1.4) was affected by a cross site scripting vulnerability that allowed an malicious user to execute arbitrary JavaScript code on an user's browser by tricking the user into typing a malicious search query, or tricking the user into clicking a link to the search page with the malicious search query prefilled. mdBook 0.4.5 fixes the vulnerability by properly escaping the search query. Owners of websites built with mdBook have to upgrade to mdBook 0.4.5 or greater and rebuild their website contents with it.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rust-lang mdbook

Vendor Advisories

The search feature of mdBook (introduced in version 014) was affected by a cross site scripting vulnerability that allowed an attacker to execute arbitrary JavaScript code on an user's browser by tricking the user into typing a malicious search query, or tricking the user into clicking a link to the search page with the malicious search query pre ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2020-26297: mdBook XSS <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Pietro Albini &lt;pietro () pietroalbi ...

Github Repositories

just a tiny diary written about my daily activities like the classes in Univ.; reading papers, articles, or books

daily_log just a tiny diary written about my daily activities like the classes in Univ; reading papers, articles, or books Published at Here use github pages How is this page generated ? use mdBook to generate html, css, js published with GitHub Pages leverage GitHub Actions to reflect the changes to published web page (see following section)   customize a li

just a tiny diary written about my daily activities like the classes in Univ.; reading papers, articles, or books

daily_log just a tiny diary written about my daily activities like the classes in Univ; reading papers, articles, or books Published at Here use github pages How is this page generated ? use mdBook to generate html, css, js published with GitHub Pages leverage GitHub Actions to reflect the changes to published web page (see following section)   customize a li