Description
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.
Remediation
References
https://github.com/sparksuite/simplemde-markdown-editor/issues/721
Related Vulnerabilities
CVE-2022-4742 Vulnerability in npm package json-pointer
CVE-2021-39154 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2017-16188 Vulnerability in npm package reecerver
CVE-2021-22964 Vulnerability in npm package fastify-static
CVE-2023-38286 Vulnerability in maven package org.thymeleaf:thymeleaf