CVE-2017-20239

MEDIUM

MDwiki Cross-Site Scripting via Location Hash Parameter

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-20239. PoCs published by evi1m0.

AI-analyzed exploit summary The writeup details a vulnerability in MDwiki where improper handling of the location.hash value leads to XSS via dynamically loaded content. The analysis includes code snippets and a PoC demonstrating how arbitrary JavaScript can be executed.

Description

MDwiki contains a cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript by injecting malicious code through the location hash parameter. Attackers can craft URLs with JavaScript payloads in the hash fragment that are parsed and rendered without sanitization, causing the injected scripts to execute in the victim's browser context.

Exploits (1)

exploitdb WRITEUP VERIFIED
by evi1m0 · webappsmultiple
https://www.exploit-db.com/exploits/46097

The writeup details a vulnerability in MDwiki where improper handling of the location.hash value leads to XSS via dynamically loaded content. The analysis includes code snippets and a PoC demonstrating how arbitrary JavaScript can be executed.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: MDwiki (version not specified)
No auth needed
Prerequisites: Victim must visit a crafted URL with a malicious hash fragment
devstral-2 · analyzed Apr 12, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit
ExploitDB-46097
https://www.exploit-db.com/exploits/46097
Third Party Advisory third-party-advisory
VulnCheck Advisory: MDwiki Cross-Site Scripting via Location Hash Parameter
https://www.vulncheck.com/advisories/mdwiki-cross-site-scripting-via-location-hash-parameter

Scores

CVSS v3 6.1
EPSS 0.0027
EPSS Percentile 17.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
dynalon/mdwiki 0.6.2
Dynalon/MDwiki 0.6.2
Published Apr 12, 2026
Tracked Since Apr 12, 2026