Description
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's.
Remediation
References
http://www.openwall.com/lists/oss-security/2014/05/13/1
http://www.openwall.com/lists/oss-security/2014/05/15/2
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3743
https://nodesecurity.io/advisories/marked_multiple_content_injection_vulnerabilities
Related Vulnerabilities
CVE-2022-40705 Vulnerability in maven package soap:soap
CVE-2022-36909 Vulnerability in maven package org.jenkins-ci.plugins:openshift-deployer
CVE-2017-5858 Vulnerability in npm package converse.js
CVE-2011-4367 Vulnerability in maven package org.apache.myfaces.core:myfaces-impl
CVE-2023-34468 Vulnerability in maven package org.apache.nifi:nifi-dbcp-base