cve/2020/CVE-2020-11888.md
2024-06-09 00:33:16 +00:00

729 B

CVE-2020-11888

Description

python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.

POC

Reference

Github

No PoCs found on GitHub currently.