Description
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.
Remediation
References
https://github.com/sparksuite/simplemde-markdown-editor/issues/721
Related Vulnerabilities
CVE-2021-25646 Vulnerability in maven package org.apache.druid:druid-core
CVE-2022-24197 Vulnerability in maven package com.itextpdf:itext7-core
CVE-2023-29566 Vulnerability in npm package dawnsparks-node-tesseract
CVE-2019-11819 Vulnerability in maven package org.opencms:org.opencms.workplace.tools.accounts