CVE-2021-47838
HIGHMarkright 1.0 - Stored Cross-Site Scripting via Crafted Markdown Files
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47838. PoCs published by TaurusOmar.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Markright 1.0, allowing an attacker to execute arbitrary JavaScript code via a malicious markdown file. The payload includes a reverse shell attempt and a calculator execution, leveraging the `onerror` event of an audio tag.
Description
Markright 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to embed malicious payloads in markdown files. Attackers can upload specially crafted markdown files that execute arbitrary JavaScript when opened, potentially enabling remote code execution on the victim's system.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Markright 1.0, allowing an attacker to execute arbitrary JavaScript code via a malicious markdown file. The payload includes a reverse shell attempt and a calculator execution, leveraging the `onerror` event of an audio tag.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N