Cross-site Scripting in Documize
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          May 18, 2021 
          to the GitHub Advisory Database
          •
          Updated Feb 14, 2023 
      
  
Package
Affected versions
< 3.5.1
  Patched versions
3.5.1
  Description
        Reviewed
      May 17, 2021 
    
  
        Published to the GitHub Advisory Database
      May 18, 2021 
    
  
        Last updated
      Feb 14, 2023 
    
  
domain/section/markdown/markdown.go in Documize before 3.5.1 mishandles untrusted Markdown content. This was addressed by adding the bluemonday HTML sanitizer to defend against XSS.
References