Описание
SimpleMDE XSS Vulnerability
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.
Пакеты
Наименование
simplemde
npm
Затронутые версииВерсия исправления
<= 1.11.2
Отсутствует
Связанные уязвимости
CVSS3: 6.1
nvd
больше 7 лет назад
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.