Description
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
Remediation
References
https://github.com/pandao/editor.md/issues/709
Related Vulnerabilities
CVE-2020-26291 Vulnerability in maven package org.webjars.bower:urijs
CVE-2021-43843 Vulnerability in npm package jsx-slack
CVE-2022-39353 Vulnerability in maven package org.webjars.npm:xmldom__xmldom
CVE-2021-32831 Vulnerability in npm package total.js
CVE-2021-21353 Vulnerability in maven package org.webjars.npm:pug-code-gen