CVE-2020-7680

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
20/07/2020
Last modified:
24/02/2021

Description

docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary JavaScript/HTML inside docsify page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:docsifyjs:docsify:*:*:*:*:*:*:*:* 4.11.4 (excluding)