A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: scheme) inside the document may allow an attacker to execute an arbitrary script on the PC of the user using marktext.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-03T02:31:59.012Z
Reserved: 2022-02-17T00:00:00
Link: CVE-2022-21158

No data.

Status : Modified
Published: 2022-03-10T17:45:09.703
Modified: 2024-11-21T06:44:00.680
Link: CVE-2022-21158

No data.