CVE-2014-5144
MEDIUMTelescope < 0.9.0 - Authenticated Stored Cross-Site Scripting via Markdown
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-5144. PoCs published by shubs.
AI-analyzed exploit summary The exploit demonstrates a persistent XSS vulnerability in Telescope <= 0.9.2 due to insufficient input sanitization when parsing markdown. It provides specific attack vectors (e.g., javascript: and data: URIs) that execute when rendered as links.
Description
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted markdown.
Exploits (1)
The exploit demonstrates a persistent XSS vulnerability in Telescope <= 0.9.2 due to insufficient input sanitization when parsing markdown. It provides specific attack vectors (e.g., javascript: and data: URIs) that execute when rendered as links.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N