CVE Vulnerabilities

CVE-2025-46654

Improper Protection of Alternate Path

Published: Apr 26, 2025 | Modified: Apr 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.

Weakness

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Potential Mitigations

References