Описание
Vditor allows Cross-site Scripting via an attribute of an A element
Vditor 3.10.3 allows XSS via an attribute of an A element.
NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.
Пакеты
Наименование
vditor
npm
Затронутые версииВерсия исправления
= 3.10.3
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
почти 2 года назад
Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.