CVE-2021-25987
30.11.2021, 14:15
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post body and tags dont sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.
| Vendor | Product | Version |
|---|---|---|
| hexo | hexo | 0.0.1 ≤ 𝑥 ≤ 5.4.0 |
𝑥
= Vulnerable software versions
References