CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.
References
Link Resource
https://github.com/hackmdio/codimd/issues/1263 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-08-23T03:19:57

Updated: 2019-08-23T03:19:57

Reserved: 2019-08-22T00:00:00


Link: CVE-2019-15499

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-08-23T04:15:11.490

Modified: 2019-10-09T12:51:22.237


Link: CVE-2019-15499

JSON object: View

cve-icon Redhat Information

No data.

CWE