Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-42hx-vrxx-5r6v

Опубликовано: 25 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Jodit Editor vulnerable to Cross-site Scripting

Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.

Пакеты

Наименование

jodit

npm
Затронутые версииВерсия исправления

<= 3.24.2

Отсутствует

EPSS

Процентиль: 32%
0.00121
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.

EPSS

Процентиль: 32%
0.00121
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79