CVE-2021-25987
30.11.2021, 14:15
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post body and tags dont sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.
Vendor | Product | Version |
---|---|---|
hexo | hexo | 0.0.1 ≤ 𝑥 ≤ 5.4.0 |
𝑥
= Vulnerable software versions
References