Junglewise Threat Intelligence

CVE-2017-20239: Dynalon MDwiki XSS via location hash parameter

CVE-2017-20239 · Severity: medium · CVSS 6.1 · Published 2026-04-12

Executive brief

MDwiki, a client-side wiki and content management system, is vulnerable to a security flaw that allows attackers to run malicious code in a user's web browser. By tricking a user into clicking a specially crafted link, an attacker can execute unauthorized scripts to steal session information or perform actions on the user's behalf. This occurs because the software does not properly check data provided in the web address before displaying it.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in MDwiki versions 0.6.2 and earlier. The vulnerability is located in the `n()` function within `mdwiki.min.js`, which extracts data from the `window.location.hash` (the URL fragment) and assigns it to `a.md.mainHref`. This value is subsequently used in an AJAX request to fetch content that is passed to the `marked()` function and rendered into the `#md-content` element without sufficient sanitization. An attacker can exploit this by hosting a malicious Markdown file on a server with permissive CORS headers and crafting a URL that points MDwiki to that file, leading to arbitrary JavaScript execution in the context of the victim's browser.

Affected products

  • Dynalon MDwiki <= 0.6.2

Timeline

  • 2017-03-02: disclosed: Original exploit published on Exploit-DB
  • 2026-04-12: advisory: CVE published via VulnCheck/NVD

References