Description
Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG element, a related issue to CVE-2018-7035.
Remediation
References
https://github.com/gleez/cms/issues/796
https://github.com/TylerGarlick/angular-redactor/issues/77
Related Vulnerabilities
CVE-2022-2564 Vulnerability in maven package org.webjars.npm:mongoose
CVE-2022-45398 Vulnerability in maven package org.zeroturnaround:cluster-stats
CVE-2017-16104 Vulnerability in npm package citypredict.whauwiller
CVE-2023-50137 Vulnerability in maven package com.jfinal:jfinal
CVE-2020-28426 Vulnerability in npm package kill-process-on-port