Vulnerability Description
Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the design of the "source code mode" feature, which parses HTML even though HTML support is not one of the primary advertised roles of the product.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Marktext | Marktext | <= 0.16.2 |
Related Weaknesses (CWE)
References
- https://github.com/marktext/marktext/issues/2360ExploitThird Party Advisory
- https://github.com/marktext/marktext/issues/2360ExploitThird Party Advisory
FAQ
What is CVE-2020-27176?
CVE-2020-27176 is a vulnerability with a CVSS score of 8.3 (HIGH). Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution. NOTE: this might be considered a duplicate of CVE-2020-26870; however, it can also be considered an issue in the de...
How severe is CVE-2020-27176?
CVE-2020-27176 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27176?
Check the references section above for vendor advisories and patch information. Affected products include: Marktext Marktext.