Description
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
Remediation
References
https://github.com/pandao/editor.md/issues/715
Related Vulnerabilities
CVE-2020-28052 Vulnerability in maven package bouncycastle:bcprov-jdk14
CVE-2021-23337 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2020-14966 Vulnerability in npm package jsrsasign
CVE-2020-26938 Vulnerability in npm package oauth2-server
CVE-2020-2256 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-maven-parent