vendor:
Telescope
by:
shubs
5.4
CVSS
MEDIUM
Persistent Cross Site Scripting
79
CWE
Product Name: Telescope
Affected Version From: 2000.9.2
Affected Version To: 2000.9.2
Patch Exists: YES
Related CWE: CVE-2014-5144
CPE: a:telescopejs:telescope
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Persistent XSS via Markdown on Telescope <= 0.9.2
Telescope 0.9.2 and below suffer from a persistent cross site scripting vulnerability due to the lack of input sanitisation and validation performed when parsing markdown user input. An authenticated user can include links, images, code blocks and more through markdown, in the form of comments, posts or replies and more. As an example, the following vectors below can be used in comments, posts or replies to trigger the XSS: [notmalicious](javascript:window.onerror=alert;throw%20document.cookie) [a](data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K)
Mitigation:
Input sanitisation and validation should be performed when parsing markdown user input.