CVE
- Id
- 103409
- CVE No.
- CVE-2017-6589
- Status
- Candidate
- Description
- EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.
- Phase
- Assigned (20170309)
- Votes
- None (candidate not yet proposed)
- Comments