CVE-2021-25987

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
30/11/2021
Last modified:
30/11/2021

Description

Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hexo:hexo:*:*:*:*:*:node.js:*:* 0.0.1 (including) 5.4.0 (including)