CVE-2014-3743

Source
https://cve.org/CVERecord?id=CVE-2014-3743
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2014-3743.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2014-3743
Aliases
Downstream
Published
2020-01-06T20:15:11Z
Modified
2026-04-10T03:43:50.652327Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's.

References

Affected packages