Описание
EpicEditor XSS Vulnerability
EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.
Пакеты
Наименование
epiceditor
npm
Затронутые версииВерсия исправления
<= 0.2.3
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
почти 9 лет назад
EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.