CVE-2021-39175
- EPSS 0.6%
- Veröffentlicht 30.08.2021 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:18:47
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting the malicious code into the sl...
CVE-2021-29503
- EPSS 1.04%
- Veröffentlicht 19.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:15
HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scripting attack using the YAML-metadata of a note. An attacker with write access to a note can embed HTML tags in the Open Graph metadata...
CVE-2021-29474
- EPSS 1.6%
- Veröffentlicht 26.04.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:11
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md` files from the server's filesystem due to an improper input validation, which results in the ability to perform a relative path ...
- EPSS 1.16%
- Veröffentlicht 26.04.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:12
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to PDF. Since the code injection has to take place as note content, there f...
CVE-2021-21259
- EPSS 1.35%
- Veröffentlicht 22.01.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:52
HedgeDoc is open source software which lets you create real-time collaborative markdown notes. In HedgeDoc before version 1.7.2, an attacker can inject arbitrary JavaScript into a HedgeDoc note, which is executed when the note is viewed in slide mode...
CVE-2020-26286
- EPSS 1.42%
- Veröffentlicht 29.12.2020 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:45
HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticated attacker can upload arbitrary files to the upload storage backend including HTML, JS and PHP files. The problem is patched in H...
CVE-2020-26287
- EPSS 1.45%
- Veröffentlicht 29.12.2020 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:45
HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an attacker can inject arbitrary `script` tags in HedgeDoc notes using mermaid diagrams. Our content security policy prevents loading scripts from...