Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfmp-9999-6wqj

Опубликовано: 21 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Vditor Cross-site Scripting vulnerability

Vditor is a browser-side Markdown editor. Versions prior to 3.8.7 are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. Version 3.8.7 contains a patch for this issue.

Пакеты

Наименование

vditor

npm
Затронутые версииВерсия исправления

< 3.8.7

3.8.7

EPSS

Процентиль: 66%
0.00507
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

Vditor is a browser-side Markdown editor. Versions prior to 3.8.7 are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. Version 3.8.7 contains a patch for this issue.

EPSS

Процентиль: 66%
0.00507
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79