Skip to main content

Improper Protection of Alternate Path

CVE-2025-46654

Severity Medium
Score 4.9/10

Summary

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.

  • HIGH
  • NETWORK
  • LOW
  • CHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-424 - Improper Protection of Alternate Path

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

References

Advisory Timeline

  • Published