Описание
Cross-Site Scripting in editor.md
All versions of editor.md are vulnerable to Cross-Site Scripting. User input is insufficiently sanitized, allowing attackers to inject malicious code in payloads containing base64-encoded content.
Recommendation
No fix is currently available. Consider using an alternative module until a fix is made available.
Пакеты
Наименование
editor.md
npm
Затронутые версииВерсия исправления
= 1.5.0
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
почти 7 лет назад
Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.