CVE-2021-38186
08.08.2021, 06:15
An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HTML entities.
Vendor | Product | Version |
---|---|---|
comrak_project | comrak | 𝑥 < 0.10.1 |
𝑥
= Vulnerable software versions
References