Description
Cross-site scripting (XSS) vulnerability in plugins/markdown_plugin/_markdown.plugin.php in b2evolution before 6.8.5 allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin BulletProof Security Multiple Vulnerabilities (.51)
WordPress Plugin Facebook for WooCommerce Cross-Site Request Forgery (1.9.14)
Moodle Incorrect Authorization Vulnerability (CVE-2020-14321)
WordPress Plugin WP Super Cache Remote Code Execution (1.7.1)
Jetty Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-34429)