Description
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
Remediation
References
https://github.com/pandao/editor.md/issues/709
Related Vulnerabilities
CVE-2020-7642 Vulnerability in maven package org.webjars.bowergithub.afarkas:lazysizes
CVE-2021-23700 Vulnerability in npm package merge-deep2
CVE-2021-44138 Vulnerability in maven package com.caucho:resin
CVE-2022-25869 Vulnerability in npm package angular
CVE-2021-21165 Vulnerability in maven package org.webjars.npm:electron