CVE-2017-11593
Last modified
CVE-2017-11593 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in the Markdown Preview Plus extension before 0.5.7 for Chrome allows remote attackers to inject arbitrary web script or HTML into some web applications via the upload and display of crafted text, markdown, or rst files that are designed to be viewed in the browser as plain text, but that will be converted to HTML without proper sanitization.. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in the Markdown Preview Plus extension before 0.5.7 for Chrome allows remote attackers to inject arbitrary web script or HTML into some web applications via the upload and display of crafted text, markdown, or rst files that are designed to be viewed in the browser as plain text, but that will be converted to HTML without proper sanitization.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ooso | Markdown Preview Plus | <= 0.4.5 |
References
- https://github.com/volca/markdown-preview/issues/60Exploit, Issue Tracking, Third Party Advisory
- https://github.com/volca/markdown-preview/issues/60Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11593?
How severe is CVE-2017-11593?
How do I fix CVE-2017-11593?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-11588On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-Anne…
- CVE-2017-11589On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-Anne…
- CVE-2017-1159IBM Business Process Manager 8.0 and 8.5 could allow a remot…
- CVE-2017-11590There is a NULL pointer dereference in the caseless_hash fun…
- CVE-2017-11591There is a Floating point exception in the Exiv2::ValueType …7.5
- CVE-2017-11592There is a Mismatched Memory Management Routines vulnerabili…
- CVE-2017-11594Cross-site scripting (XSS) vulnerability in the Markdown par…
- CVE-2017-1160IBM Financial Transaction Manager for ACH Services for Multi…
- CVE-2017-11600net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, w…7
- CVE-2017-11605There is a heap based buffer over-read in LibSass 3.4.5, rel…
- CVE-2017-11608There is a heap-based buffer over-read in the Sass::Prelexer…
- CVE-2017-1161IBM API Connect 5.0.6.0 could allow a remote attacker to exe…
Are you affected by CVE-2017-11593?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
