Description
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
Remediation
References
https://github.com/pandao/editor.md/issues/634
Related Vulnerabilities
CVE-2018-16473 Vulnerability in npm package takeapeek
CVE-2020-25711 Vulnerability in maven package org.infinispan:infinispan-server-rest
CVE-2017-17868 Vulnerability in maven package com.liferay.portal:portal-service
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.codemirror:codemirror
CVE-2024-36401 Vulnerability in maven package org.geoserver.web:gs-web-app