Cross-Site Scripting Vulnerability in markdown-it Plugin by Markdown
CVE-2015-3295
5.3MEDIUM
What is CVE-2015-3295?
The markdown-it library prior to version 4.1.0 is vulnerable to a Cross-Site Scripting (XSS) attack as it fails to properly sanitize 'data:' URLs. This oversight can allow attackers to inject malicious scripts into web applications, potentially compromising user data and security. It is crucial for users of markdown-it to upgrade to the latest version to mitigate this risk.
