Vulnerability Description
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hexo-Admin Project | Hexo-Admin | <= 2.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/jaredly/hexo-admin/commits/masterPatchThird Party Advisory
- https://mega.nz/#%218MYnUQzC%21ZCqixrGyHdBhimCmrszSXdFmI2feImhuZZMcnplNBQQ
- https://www.npmjs.com/advisoriesThird Party Advisory
- https://www.npmjs.com/advisories/1211Third Party Advisory
- https://github.com/jaredly/hexo-admin/commits/masterPatchThird Party Advisory
- https://mega.nz/#%218MYnUQzC%21ZCqixrGyHdBhimCmrszSXdFmI2feImhuZZMcnplNBQQ
- https://www.npmjs.com/advisoriesThird Party Advisory
- https://www.npmjs.com/advisories/1211Third Party Advisory
FAQ
What is CVE-2019-17606?
CVE-2019-17606 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
How severe is CVE-2019-17606?
CVE-2019-17606 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17606?
Check the references section above for vendor advisories and patch information. Affected products include: Hexo-Admin Project Hexo-Admin.