Description
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
Remediation
References
https://github.com/pandao/editor.md/issues/634
Related Vulnerabilities
CVE-2021-43309 Vulnerability in npm package uri-template-lite
CVE-2023-28155 Vulnerability in npm package request
CVE-2020-7792 Vulnerability in maven package org.webjars.npm:mout
CVE-2013-5679 Vulnerability in maven package org.owasp.esapi:esapi
CVE-2022-36098 Vulnerability in maven package org.xwiki.platform:xwiki-platform-mentions-ui