CVE-2025-46654
26.04.2025, 21:15
CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.Enginsight
Vendor | Product | Version |
---|---|---|
hackmdio | codimd | 𝑥 ≤ 2.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration