CVE-2017-20239

Source
https://cve.org/CVERecord?id=CVE-2017-20239
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-20239.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-20239
Published
2026-04-12T13:16:30Z
Modified
2026-08-28T08:19:49Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

MDwiki contains a cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript by injecting malicious code through the location hash parameter. Attackers can craft URLs with JavaScript payloads in the hash fragment that are parsed and rendered without sanitization, causing the injected scripts to execute in the victim's browser context.

References

Affected packages

Git / github.com/dynalon/mdwiki

Affected ranges

Type
GIT
Repo
https://github.com/dynalon/mdwiki
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:dynalon:mdwiki:0.6.2:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0.6.2"
        },
        {
            "last_affected": "0.6.2"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

0.*
0.6.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-20239.json"