Description
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature.
Remediation
References
https://github.com/keystonejs/keystone/pull/4478
http://blog.securelayer7.net/keystonejs-open-source-penetration-testing-report/
https://www.exploit-db.com/exploits/43054/
https://packetstormsecurity.com/files/144756/KeystoneJS-4.0.0-beta.5-Unauthenticated-Stored-Cross-Site-Scripting.html
http://www.securityfocus.com/bid/101541
Related Vulnerabilities
CVE-2019-11002 Vulnerability in maven package org.webjars.npm:materialize-css
CVE-2022-21208 Vulnerability in npm package node-opcua
CVE-2021-46708 Vulnerability in maven package org.webjars.npm:swagger-ui
CVE-2022-31018 Vulnerability in maven package com.typesafe.play:play_2.13
CVE-2020-26217 Vulnerability in maven package xstream:xstream