Description
Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.
Remediation
References
https://github.com/Heartway/simditor/blob/master/simditor.docx
Related Vulnerabilities
CVE-2023-46998 Vulnerability in maven package org.webjars.bower:bootbox.js
CVE-2016-10548 Vulnerability in npm package reduce-css-calc
CVE-2017-16152 Vulnerability in npm package static-html-server
CVE-2020-36380 Vulnerability in npm package aaptjs
CVE-2021-21331 Vulnerability in maven package com.datadoghq:datadog-api-client