Security Advisory

CVE-2019-15499

6.1
MEDIUM

Vulnerability Description

CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.
Published Date August 23, 2019
Official Source NIST NVD Advisory