Description
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
Remediation
References
https://github.com/pandao/editor.md/issues/709
Related Vulnerabilities
CVE-2021-27292 Vulnerability in npm package ua-parser-js
CVE-2020-19697 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2022-37423 Vulnerability in maven package org.neo4j.procedure:apoc
CVE-2021-21429 Vulnerability in maven package org.openapitools:openapi-generator-maven-plugin