
Cloud Vulnerability DB
A community-led vulnerabilities database
A high-severity Cross-Site Scripting (XSS) vulnerability was identified in hexo-admin, affecting all versions of the package (>=0.0.0). The vulnerability was initially reported on April 14, 2019, and was later published to the GitHub Advisory Database on September 3, 2020, with the identifier GHSA-phph-xpj4-wvcv. This security issue impacts the hexo-admin package, which is a popular npm package (GitHub Advisory).
The vulnerability stems from the package's failure to properly sanitize rendered markdown content. This weakness is classified as CWE-79 (Cross-Site Scripting). The vulnerability allows attackers to execute arbitrary JavaScript code in a victim's browser when they have the ability to create new posts. The issue was confirmed through proof-of-concept demonstrations that showed successful exploitation using various payloads, including access to document.cookie and document.domain (Hexo Admin Issue).
When exploited, this vulnerability enables attackers to execute arbitrary JavaScript code in the context of other users' browsers who access the affected posts. This could potentially lead to theft of sensitive information, session hijacking, or other malicious actions performed in the context of the victim's browser session (GitHub Advisory).
The vulnerability has been demonstrated to be exploitable through the creation of new posts containing malicious payloads. A proof-of-concept exploit has been documented, showing successful execution of various JavaScript commands including access to document.cookie and document.domain (Hexo Admin Issue).
Currently, no official fix is available for this vulnerability. The recommended mitigation strategy is to consider using alternative packages until a security fix is made available. Users should exercise caution when using any version of hexo-admin, as all versions are affected by this vulnerability (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."