{"id":"CVE-2017-5553","details":"Cross-site scripting (XSS) vulnerability in plugins/markdown_plugin/_markdown.plugin.php in b2evolution before 6.8.5 allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL.","modified":"2026-07-08T11:48:41.431471Z","published":"2017-01-23T07:59:00.580Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95704"},{"type":"FIX","url":"http://b2evolution.net/downloads/6-8-5"},{"type":"FIX","url":"https://github.com/b2evolution/b2evolution/commit/ce5b36e44b714b18b0bcd34c6db0187b8d13bab8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/b2evolution/b2evolution","events":[{"introduced":"0"},{"last_affected":"551702a31751ac1f98ea89e1ef62794294f6f3a2"},{"fixed":"ce5b36e44b714b18b0bcd34c6db0187b8d13bab8"}],"database_specific":{"cpe":"cpe:2.3:a:b2evolution:b2evolution:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"6.8.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["6.8.4","6.8.3","6.8.2","6.8.1","6.8.0-beta","6.7.7","6.7.6","6.7.5","6.6.8","6.6.7","6.7.0-alpha","6.6.6","6.6.5","6.6.4","6.6.1","6.6.0","6.5.0","6.4.4-beta","6.4.3-beta","6.4.2-beta","6.1.2-alpha","6.0.0-alpha.1","6.0.0-alpha","v5.2.0-stable"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5553.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}