Description
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
Remediation
References
https://github.com/pandao/editor.md/issues/709
Related Vulnerabilities
CVE-2023-37950 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration
CVE-2019-17495 Vulnerability in maven package org.webjars:swagger-ui
CVE-2022-24697 Vulnerability in maven package org.apache.kylin:kylin-core-common
CVE-2023-26136 Vulnerability in maven package org.webjars.bowergithub.salesforce:tough-cookie