Description
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
Remediation
References
https://github.com/pandao/editor.md/issues/715
Related Vulnerabilities
CVE-2021-28165 Vulnerability in maven package org.eclipse.jetty:jetty-io
CVE-2023-26120 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2023-28709 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-43496 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-28498 Vulnerability in maven package org.webjars.npm:elliptic