Description
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
Remediation
References
https://github.com/pandao/editor.md/issues/715
Related Vulnerabilities
CVE-2020-2174 Vulnerability in maven package org.jenkins-ci.plugins:awseb-deployment-plugin
CVE-2020-7787 Vulnerability in npm package react-adal
CVE-2018-15685 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-39106 Vulnerability in maven package com.alibaba.nacos:nacos-spring-context