CNNVD-202509-2018 Information
Sep 15, 2025
cve
CNNVD ID
CNNVD-202509-2018
Related CVE
- CNNVD Published: 2025-09-15
Description (Chinese)
drawnix是plait-board开源的一个白板工具。 drawnix 0.2.1及之前版本存在跨站脚本漏洞,该漏洞源于未对用户输入内容进行清理,直接通过innerHTML插入到DOM中,可能导致跨站脚本攻击。
Description (English)
Drawnix is a whiteboard tool for plain-board open sources. Drawnix 0.2.1 and previous versions have a cross-site script loophole, which stems from the failure to clean up user input and is inserted directly into DOM through InnerHTML, which may result in a cross-site script attack.
Hazard Level
High
Vulnerability Type
跨站脚本
Affected Vendor
Plasmo
Published
2025-09-15
Last Modified
2026-02-24
References
https://github.com/plait-board/drawnix/commit/92536e63c1adcc509ac51fdd439d4794c8081c58 https://github.com/plait-board/drawnix/security/advisories/GHSA-cq57-q8hg-xhxf
Patch
https://github.com/plait-board/drawnix/releases
Share on: