cve/2021/CVE-2021-25987.md
2025-09-29 21:09:30 +02:00

864 B
Raw Blame History

CVE-2021-25987

Description

Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” dont sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.

POC

Reference

Github

No PoCs found on GitHub currently.