Description
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.
Remediation
References
https://github.com/sparksuite/simplemde-markdown-editor/issues/721
Related Vulnerabilities
CVE-2019-17352 Vulnerability in maven package com.jfinal:jfinal
CVE-2022-24822 Vulnerability in npm package @podium/layout
CVE-2020-9497 Vulnerability in maven package org.apache.guacamole:guacamole
CVE-2023-40827 Vulnerability in maven package org.pf4j:pf4j
CVE-2021-41182 Vulnerability in maven package org.webjars.bower:jquery-ui