CVE-2019-9844
09.04.2019, 02:29
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
Vendor | Product | Version |
---|---|---|
khanacademy | simple-markdown | 𝑥 < 0.4.4 |
𝑥
= Vulnerable software versions
References
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
Vendor | Product | Version |
---|---|---|
khanacademy | simple-markdown | 𝑥 < 0.4.4 |