Description
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
Remediation
References
https://github.com/pandao/editor.md/issues/612
Related Vulnerabilities
CVE-2020-36649 Vulnerability in maven package org.webjars.npm:papaparse
CVE-2022-22965 Vulnerability in maven package org.springframework.boot:spring-boot-starter-web
CVE-2018-20801 Vulnerability in npm package highcharts
CVE-2021-24122 Vulnerability in maven package org.apache.tomcat:tomcat-catalina