Description
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
Remediation
References
https://github.com/pandao/editor.md/issues/612
Related Vulnerabilities
CVE-2020-13951 Vulnerability in maven package org.apache.openmeetings:openmeetings-server
CVE-2022-2596 Vulnerability in npm package node-fetch
CVE-2020-36179 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-6563 Vulnerability in maven package org.keycloak:keycloak-model-jpa
CVE-2023-46499 Vulnerability in npm package @evershop/evershop