Описание
Vditor is a browser-side Markdown editor. Versions prior to 3.8.7 are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. Version 3.8.7 contains a patch for this issue.
Ссылки
- PatchThird Party Advisory
- Issue TrackingThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.8.7 (исключая)
cpe:2.3:a:b3log:vditor:*:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00507
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
EPSS
Процентиль: 66%
0.00507
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
CWE-79