PT-2026-32176 · Dynalon+1 · Mdwiki
CVE-2017-20239
·
Published
2026-04-12
·
Updated
2026-04-12
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MDwiki (affected versions not specified)
Description
Cross-site scripting occurs when the application fails to sanitize the location hash parameter, allowing remote attackers to execute arbitrary JavaScript. By crafting URLs with malicious payloads in the hash fragment, an attacker can cause the scripts to execute within the victim's browser context.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mdwiki