Description
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
Remediation
References
https://github.com/pandao/editor.md/issues/634
Related Vulnerabilities
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-services
CVE-2022-24377 Vulnerability in npm package cycle-import-check
CVE-2020-5229 Vulnerability in maven package org.opencastproject:opencast-common-jpa-impl
CVE-2022-22947 Vulnerability in maven package org.springframework.cloud:spring-cloud-gateway
CVE-2020-14968 Vulnerability in maven package org.webjars.npm:jsrsasign