Description
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
Remediation
References
https://github.com/pandao/editor.md/issues/612
Related Vulnerabilities
CVE-2020-13410 Vulnerability in npm package aedes
CVE-2020-28500 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2017-16125 Vulnerability in npm package rtcmulticonnection-client
CVE-2023-49210 Vulnerability in npm package openssl
CVE-2022-45689 Vulnerability in maven package cn.hutool:hutool-json