An issue exists in the comrak crate prior to 0.9.1 for Rust. XSS can occur because the protection mechanism for data: and javascript: URIs is case-sensitive, allowing (for example) Data: to be used in an attack.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
comrak project comrak |