CVE-2021-25987 (hexo)
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “bodyâ€� and “tagsâ€� don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code. Devamını Oku