---
id: CVE-2017-20239
title: MDwiki Cross-Site Scripting via Location Hash Parameter
summary: >-
  MDwiki contains a cross-site scripting vulnerability that allows remote
  attackers to execute arbitrary JavaScript by injecting malicious code through
  the location hash parameter. Attackers can craft URLs with JavaScript payloads
  in the h…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-79
vendor: Dynalon
product: MDwiki
affected:
  - MDwiki 0.6.2
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-04-13T15:51:20.583814Z'
exploitAvailable: true
published: '2026-04-12'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:01.406Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2017-20239'
references:
  - url: 'https://www.exploit-db.com/exploits/46097'
    label: ExploitDB-46097
  - url: >-
      https://www.vulncheck.com/advisories/mdwiki-cross-site-scripting-via-location-hash-parameter
    label: >-
      VulnCheck Advisory: MDwiki Cross-Site Scripting via Location Hash
      Parameter
tags:
  - cve.org
  - exploit-available
epss: 0.00266
epssPercentile: 0.16728
ingestedAt: '2026-10-01T15:48:17.893Z'
---

## Overview

MDwiki contains a cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript by injecting malicious code through the location hash parameter. Attackers can craft URLs with JavaScript payloads in the hash fragment that are parsed and rendered without sanitization, causing the injected scripts to execute in the victim's browser context.

## Affected

- `MDwiki 0.6.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
