Description
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
Remediation
References
https://github.com/pandao/editor.md/issues/709
Related Vulnerabilities
CVE-2020-24660 Vulnerability in npm package node-lemonldap-ng-handler
CVE-2009-3579 Vulnerability in maven package org.mortbay.jetty:jetty
CVE-2018-20677 Vulnerability in maven package org.webjars:bootstrap-sass
CVE-2020-7774 Vulnerability in npm package y18n
CVE-2021-39236 Vulnerability in maven package org.apache.ozone:ozone-main