VulnerabilityModified
CVE-2021-25987
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS.
MEDIUM 4.6EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- hexo/hexo
- Source
- vulnerabilitylab@mend.io
References
- https://github.com/hexojs/hexo/commit/5170df2d3fa9c69e855c4b7c2b084ebfd92d5200Patch, Third Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25987Third Party Advisory
- https://github.com/hexojs/hexo/commit/5170df2d3fa9c69e855c4b7c2b084ebfd92d5200Patch, Third Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25987Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.