Executive brief
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
Affected products
- PyPI markdown2
Junglewise Threat Intelligence
CVE-2020-11888 · Severity: low · CVSS 3.1 · Published 2020-04-20
Technologies: markdown2 (PyPI). Vendors: PyPI.
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.