Description
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
Remediation
References
https://github.com/pandao/editor.md/issues/634
Related Vulnerabilities
CVE-2020-28481 Vulnerability in maven package org.webjars.npm:socket.io
CVE-2023-26158 Vulnerability in maven package org.webjars.npm:mockjs
CVE-2021-27185 Vulnerability in npm package samba-client
CVE-2022-43183 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2018-18854 Vulnerability in maven package io.spray:spray-json_2.12