CVE-2019-15499
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute,
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.
MEDIUM · CVSS 6.1
EPSS 0.0024
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0