MEDIUM6.1
GHSA-g784-q3p3-26rm
hexo-admin plugin for Node.js XSS Vulnerability
Details
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/hexo-admin
Introduced in:
0No fixed version published yet for hexo-admin (npm). Pin to a known-safe version or switch to an alternative.