Content Injection

Module: remarkable

Published: November 13th, 2014

Reported by: Adam Baldwin

CVE-NONE

CWE-94

Vulnerable: <1.4.1
Patched: >=1.4.1

Overview

Versions 1.4.0 and earlier of remarkable are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions of remarkable did not properly whitelist link protocols, and consequently allowed javascript: to be used.

Proof of Concept

Markdown Source:

[link](<javascript:alert(1)>)

Rendered HTML:

<a href="javascript:alert(1)">link</a>

Remediation

Update to version 1.4.1 or later

References