Description
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
Remediation
References
https://github.com/pandao/editor.md/issues/709
Related Vulnerabilities
CVE-2017-16008 Vulnerability in maven package org.webjars:i18next
CVE-2022-45690 Vulnerability in maven package cn.hutool:hutool-json
CVE-2022-45394 Vulnerability in maven package org.jenkins-ci.plugins:delete-log-plugin
CVE-2021-23433 Vulnerability in npm package algoliasearch-helper
CVE-2023-29204 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore