Description
vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require('child_process').execSync('calc.exe') on Windows and a similar attack on macOS.
Remediation
References
https://github.com/yoshuawuyts/vmd/issues/137
Related Vulnerabilities
CVE-2023-47323 Vulnerability in maven package org.silverpeas.core:silverpeas-core-api
CVE-2017-12615 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2019-11002 Vulnerability in npm package materialize-css
CVE-2012-0392 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-28164 Vulnerability in maven package org.eclipse.jetty:jetty-webapp