Skip to content

DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js...

Critical severity Unreviewed Published Aug 19, 2023 to the GitHub Advisory Database • Updated Apr 4, 2024

Package

No package listedSuggest a package

Affected versions

Unknown

Patched versions

Unknown

Description

DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows arbitrary JavaScript code to run in the context of MarkText main window. This vulnerability can be exploited if a user copies text from a malicious webpage and paste it into MarkText.

References

Published by the National Vulnerability Database Aug 19, 2023
Published to the GitHub Advisory Database Aug 19, 2023
Last updated Apr 4, 2024

Severity

Critical

Weaknesses

CVE ID

CVE-2023-2318

GHSA ID

GHSA-jv63-mj7w-v6v9

Source code

No known source code

Dependabot alerts are not supported on this advisory because it does not have a package from a supported ecosystem with an affected and fixed version.

Learn more about GitHub language support

Checking history
See something to contribute? Suggest improvements for this vulnerability.