CVE-2018-6806

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
07/02/2018
Last modified:
11/09/2019

Description

Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaScript code, e.g., making XMLHttpRequest calls.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:marked_2_project:marked_2:*:*:*:*:*:*:*:* 2.5.11 (including)